THREAT OPS › Threat News › [GHSA] GHSA-49mq-fc6q-3h46 (high) — Token Optimizer MCP: OS command injection in smart_user via username in get-user-info
[GHSA] GHSA-49mq-fc6q-3h46 (high) — Token Optimizer MCP: OS command injection in smart_user via username in get-user-info
GHSA-49mq-fc6q-3h46 Severity: high CVE: CVE-2026-55157
Token Optimizer MCP: OS command injection in smart_user via username in get-user-info
### Summary
`token-optimizer-mcp` is vulnerable to OS command injection in the `smart_user` tool.
The `get-user-info` operation accepts a user-controlled `username` argument and later interpolates it into a shell command executed through `execAsync()`:
`
Indicators of compromise
- CVE-2026-55157cve
Original source: https://github.com/advisories/GHSA-49mq-fc6q-3h46