THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-76pc-mqxp-3rq5 (medium) — Token Optimizer MCP: Unauthenticated Path Traversal in Dashboard Session Log API Endpoints

[GHSA] GHSA-76pc-mqxp-3rq5 (medium) — Token Optimizer MCP: Unauthenticated Path Traversal in Dashboard Session Log API Endpoints

highgithub_advisoriesPublished 2026-08-14

GHSA-76pc-mqxp-3rq5 Severity: medium CVE: CVE-2026-55156

Token Optimizer MCP: Unauthenticated Path Traversal in Dashboard Session Log API Endpoints

# Unauthenticated Path Traversal in Dashboard Session Log API Endpoints

| Field | Value | | ---------------- | ----- | | Repository | ooples/token-optimizer-mcp | | Affected version | 5.0.1 (commit 8137147) | | Vulnerability | CW

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-76pc-mqxp-3rq5