THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-49mq-fc6q-3h46 (high) — Token Optimizer MCP: OS command injection in smart_user via username in get-user-info

[GHSA] GHSA-49mq-fc6q-3h46 (high) — Token Optimizer MCP: OS command injection in smart_user via username in get-user-info

medgithub_advisoriesPublished 2026-08-14

GHSA-49mq-fc6q-3h46 Severity: high CVE: CVE-2026-55157

Token Optimizer MCP: OS command injection in smart_user via username in get-user-info

### Summary

`token-optimizer-mcp` is vulnerable to OS command injection in the `smart_user` tool.

The `get-user-info` operation accepts a user-controlled `username` argument and later interpolates it into a shell command executed through `execAsync()`:

`

Indicators of compromise

Original source: https://github.com/advisories/GHSA-49mq-fc6q-3h46