External risk intelligence

metatool-ai MetaMCP Unauthenticated Code Execution via Internal Proxy

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-79538

The vulnerability exists in an internal inspector proxy endpoint designed for local STDIO transport communication. This component is intended for developer-focused tooling or internal service orchestration rather than public-facing network services, making it highly unlikely to be exposed to the public internet in standard deployments.

Code Injection

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in the metatool-ai MetaMCP software that could allow for code execution. This issue stems from an internal proxy endpoint that handles standard input/output communication. While the impact is generally considered low due to its internal nature, it is important to confirm if this specific component is exposed externally in your environment.

  • Internal tool allows remote code execution.
  • Assess if this internal tool is exposed externally.
  • Confirm relevance and potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending a request to a specific internal network endpoint that is not designed for public access. If this endpoint is exposed, the attacker could trigger a flaw in how the system handles standard input/output, potentially leading to code execution.

  • Requires network access to an internal endpoint.
  • Triggers by sending a request to `/mcp-proxy/server/stdio`.
  • Allows unauthenticated code execution.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to execute arbitrary code on systems running metatool-ai MetaMCP when the internal MCP inspector proxy endpoint is accessible. This could impact the integrity and availability of the affected service.

  • System code execution.
  • Unauthenticated network access.
  • Service compromise.

Operational Fix

Recommended remediation, mitigation, and detection steps

The criticality of this vulnerability in the internal MCP inspector proxy endpoint suggests that platform or infrastructure teams responsible for the metatool-ai MetaMCP deployment should prioritize investigation. The first practical step involves identifying all instances of MetaMCP, assessing their accessibility (particularly if the internal proxy is exposed externally), and determining business criticality to inform a targeted remediation plan.

  • Platform/Infrastructure team owns the issue.
  • Verify internal proxy endpoint accessibility.
  • Plan risk-based remediation or mitigation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is metatool-ai MetaMCP?

MetaMCP is a software component by metatool-ai used for bridging AI models with external tools via the Model Context Protocol. It is primarily used by developers to manage service orchestration and standardized communication between automated systems and their local or server-side toolkits.

How does CVE-2026-79538 enable code execution?

This vulnerability is classified as CWE-94, or Improper Control of Generation of Code. The flaw exists in an internal proxy endpoint designed to handle STDIO transport. Because the system fails to properly validate requests sent to this specific route, an attacker can supply input that the software mistakenly processes as executable commands.

Do I need to be authenticated to trigger this flaw?

No, authentication is not required to trigger this issue. However, the flaw only occurs when an attacker can reach the specific internal endpoint at /mcp-proxy/server/stdio. Requests sent to other parts of the application or those made while the proxy is inactive do not initiate the vulnerable code path.

Is my environment at risk from this CVE?

According to Halo Surface Signal, it is very unlikely that your environment is at risk. The affected endpoint is intended for local STDIO communication and developer tooling, not public network traffic. You are only likely to be concerned if your configuration has inadvertently exposed this internal service to the public internet.

How should I respond to this advisory?

Start by identifying all deployments of MetaMCP within your infrastructure. Once located, verify that the /mcp-proxy/server/stdio endpoint is restricted and not accessible from outside your private network. Prioritize these checks for any instances that reside on internet-facing systems, then plan further risk-based mitigations with your infrastructure team.

References