metatool-ai MetaMCP through 2.4.22 contains an insecure direct object reference (IDOR) in the MCP transport session dispatch. The session store (getSession in session-lifetime-manager.ts) is keyed only by the client-supplied mcp-session-id header with no owner
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-102249 | 7.3 HIGH | REBUILD file-editor-save authorization |
| CVE-2026-102248 | 7.3 HIGH | Rebuild Login Endpoint login improper authentication |
| CVE-2026-102247 | 6.8 MEDIUM | FastAdmin Database Management database.php unnecessary privileges |
| CVE-2026-77177 | CVE-2026-77177 | |
| CVE-2026-94954 | CVE-2026-94954 | |
| CVE-2026-94953 | CVE-2026-94953 | |
| CVE-2026-79535 | CVE-2026-79535 | |
| CVE-2026-79536 | CVE-2026-79536 | |
| CVE-2024-31026 | CVE-2024-31026 | |
| CVE-2026-79538 | CVE-2026-79538 | |
| CVE-2026-79534 | CVE-2026-79534 | |
| CVE-2024-31027 | CVE-2024-31027 | |
| CVE-2026-79417 | CVE-2026-79417 | |
| CVE-2026-79403 | CVE-2026-79403 |
No comments yet