THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-mw6r-2hvm-4rp2 (critical) — qwed-mcp has Unsafe SymPy `parse_expr()` Remote Code Execution via Unsanitized Math Expression Input

[GHSA] GHSA-mw6r-2hvm-4rp2 (critical) — qwed-mcp has Unsafe SymPy `parse_expr()` Remote Code Execution via Unsanitized Math Expression Input

highgithub_advisoriesPublished 2026-08-25

GHSA-mw6r-2hvm-4rp2 Severity: critical CVE: CVE-2026-55546

qwed-mcp has Unsafe SymPy `parse_expr()` Remote Code Execution via Unsanitized Math Expression Input

### Summary

`verify_math_expression()` in `qwed-mcp` v0.2.0 passes attacker-controlled strings directly to SymPy's `parse_expr()` without restricting `global_dict` or validating the expression's AST. Because `parse_expr()` internally cal

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-mw6r-2hvm-4rp2