THREAT OPS › Threat News › [GHSA] GHSA-mw6r-2hvm-4rp2 (critical) — qwed-mcp has Unsafe SymPy `parse_expr()` Remote Code Execution via Unsanitized Math Expression Input
[GHSA] GHSA-mw6r-2hvm-4rp2 (critical) — qwed-mcp has Unsafe SymPy `parse_expr()` Remote Code Execution via Unsanitized Math Expression Input
GHSA-mw6r-2hvm-4rp2 Severity: critical CVE: CVE-2026-55546
qwed-mcp has Unsafe SymPy `parse_expr()` Remote Code Execution via Unsanitized Math Expression Input
### Summary
`verify_math_expression()` in `qwed-mcp` v0.2.0 passes attacker-controlled strings directly to SymPy's `parse_expr()` without restricting `global_dict` or validating the expression's AST. Because `parse_expr()` internally cal
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- 54ac682699407310b5a71fbaed8c33f581b84301sha1
- CVE-2026-55546cve
Original source: https://github.com/advisories/GHSA-mw6r-2hvm-4rp2