CVE-2026-55157 Details
Description
Token Optimizer MCP measures token savings per AI coding agent, optimizes context, and shares a live local knowledge graph across 16 CLI clients. Prior to version 5.1.0, token-optimizer-mcp is vulnerable to OS command injection in the smart_user tool. Any MCP client that can call the smart_user tool can execute arbitrary shell commands through the username argument of the get-user-info operation. The commands execute with the privileges of the user running the token-optimizer-mcp server. This issue has been patched in version 5.1.0.
A command injection vulnerability has been identified in the Ooples Token Optimizer MCP version 5.0.1, specifically within the smart_user tool. The issue arises in the get-user-info operation, where the username argument is improperly sanitized before being passed into a shell command. This flaw allows any MCP client that can invoke the smart_user tool to execute arbitrary commands on the server where Token Optimizer MCP is running, using the privileges of the user executing the MCP server.
Users can upgrade to Token Optimizer MCP version 5.1.0 or later, where this vulnerability has been patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 28, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/ooples/token-optimizer-mcp/commit/b4ee96dac799cbfba0a9f9c17844ce9d613cbcc7 | [email protected] | Source CodeVendor |
| https://github.com/ooples/token-optimizer-mcp/releases/tag/v5.1.0 | [email protected] | Release NotesVendor |
| https://github.com/ooples/token-optimizer-mcp/security/advisories/GHSA-49mq-fc6q-3h46 | [email protected] | AdvisoryExploitRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ooples Token Optimizer MCP | 5.0.1 (semver) |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 28, 2026 | New CVE Received | [email protected] |
Volerion