All 2 CVE vulnerabilities found in token-optimizer-mcp, with AI-generated Chinese analysis, references, and POCs.
Vendor: ooples
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-55156 | Token Optimizer MCP: Unauthenticated Path Traversal in Dashboard Session Log API Endpoints CWE-22 | 5.3 | Medium | 2026-09-28 |
| CVE-2026-55157 | Token Optimizer MCP: OS command injection in smart_user via username in get-user-info CWE-78 | 8.4 | High | 2026-09-28 |
All 2 known CVE vulnerabilities affecting token-optimizer-mcp with full Chinese analysis, references, and POCs where available.