PULSE
FEED
ransommedusalocker reclama a PKSF — Palli Karma-Sahayak Foundation · BD · Financial Servicesransomemperador reclama a Amazon Informatica · BR · Technologyransomqilin reclama a New World Diagnostics · PH · Healthcareransompayload reclama a Netech (Neeser Technik AG) · CH · Manufacturingransommedusalocker reclama a Juntadeandalucia · ES · Government & Defenseransommedusalocker reclama a Premiumfruits · ES · Agriculture and Food Productionransominterlock reclama a The Center for Kidney Care · US · Healthcareransomsilentransomgroup reclama a S...d · Not Foundransomakira reclama a Geebee Garments · Retail & E-Commerceransomakira reclama a Knit · Technologyransomqilin reclama a SKLG · JP · Not Foundransommedusalocker reclama a ATCO Ltd · CA · Energy & Utilitiesransompear reclama a Kellys Home Center · US · Retail & E-Commerceransomqilin reclama a Nissho Electric Manufacturing Co., Ltd. · JP · Manufacturingransommedusalocker reclama a PKSF — Palli Karma-Sahayak Foundation · BD · Financial Servicesransomemperador reclama a Amazon Informatica · BR · Technologyransomqilin reclama a New World Diagnostics · PH · Healthcareransompayload reclama a Netech (Neeser Technik AG) · CH · Manufacturingransommedusalocker reclama a Juntadeandalucia · ES · Government & Defenseransommedusalocker reclama a Premiumfruits · ES · Agriculture and Food Productionransominterlock reclama a The Center for Kidney Care · US · Healthcareransomsilentransomgroup reclama a S...d · Not Foundransomakira reclama a Geebee Garments · Retail & E-Commerceransomakira reclama a Knit · Technologyransomqilin reclama a SKLG · JP · Not Foundransommedusalocker reclama a ATCO Ltd · CA · Energy & Utilitiesransompear reclama a Kellys Home Center · US · Retail & E-Commerceransomqilin reclama a Nissho Electric Manufacturing Co., Ltd. · JP · Manufacturing
← Todos los CVEs
CVE Watch28 sept 2026

CVE-2026-55157

Token Optimizer MCP measures token savings per AI coding agent, optimizes context, and shares a live local knowledge graph across 16 CLI cli

CVSS

8.4

Alto

EPSS

—

KEV

—

Exploit Today

—

0-100

Publicado: 28 sept 2026 · Última mod.: 28 sept 2026 · CWE-78

EPSS · 30d

Sin historial EPSS suficiente todavía.

Descripción técnica

Token Optimizer MCP measures token savings per AI coding agent, optimizes context, and shares a live local knowledge graph across 16 CLI clients. Prior to version 5.1.0, token-optimizer-mcp is vulnerable to OS command injection in the smart_user tool. Any MCP client that can call the smart_user tool can execute arbitrary shell commands through the username argument of the get-user-info operation. The commands execute with the privileges of the user running the token-optimizer-mcp server. This issue has been patched in version 5.1.0.

Referencias oficiales
CVEs relacionados
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-75600—
—
———FreePBX is an open source IP PBX. Prior to version 17.0.9, authenticated users who are authorized to access the GraphQL api module interface of FreePBX are able to execute arbitrary shell commands. Authenticated access to the api module is required. The PBX API module's documentation generator accepts an authenticated host parameter and uses it to build a shell command. The code path validates the generated OAuth access token before execution, but it does not validate or escape host. Compromise results in authenticated arbitrary shell command execution as the FreePBX web/PBX service user (typically asterisk.). This issue has been patched in version 17.0.9.4h
CVE-2026-54674—
—
———FreePBX is an open source IP PBX. Prior to versions 16.0.39 and 17.0.7, users authenticated via User Control Panel (UCP) are able to execute arbitrary commands on the PBX as the webserver user (typically asterisk) using specially crafted HTTP strings. Authenticated access to UCP is required. Note that this is often more common for less-privileged users to have UCP access vs. the Administrator Control Panel (ACP) access (which is usually FreePBX higher-level administrator accounts only). Insufficient sanitization of certain URL parameters utilized by UCP did not fully account for malicious strings in these fields. This could result in binaries being executed on the host server by carefully chaining commands. This issue has been patched in versions 16.0.39 and 17.0.7.3h
CVE-2026-45562—
—
———FreePBX is an open source IP PBX. Prior to versions 16.0.4 and 17.0.6, the FreePBX Music on Hold (MoH) module contains a critical security flaw that allows authenticated attackers to execute arbitrary system commands with the privileges of the Asterisk service. Authentication with an existing FreePBX administrator account is required. The root cause lies in the fact that the module accepts a POST parameter that defines a custom Asterisk application, which is then stored in the database without any sanitization. Later, this data is written directly to the musiconhold_additional.conf configuration file without validation. Since Asterisk reads this configuration file and executes the specified application, an attacker can inject arbitrary commands that will be executed with Asterisk's permissions. This issue has been patched in versions 16.0.4 and 17.0.6.3h
CVE-2026-87969—
—
———An OS command injection vulnerability in the WatchGuard AP diagnostic CLI allows an authenticated administrator to execute arbitrary operating system commands by supplying crafted input.4h
CVE-2026-86102—
—
———An OS command injection vulnerability in the WatchGuard AP internal API service allows an attacker with network access to the AP to execute arbitrary shell commands on the underlying operating system.4h
CVE-2026-10107610.0 CRÍ
—
———A vulnerability was detected in Netcore NR289-GE 1.4.5102. This affects the function system of the file /set_ntp_server_ip.cgi of the component CGI Handler. The manipulation of the argument ntp_ip results in os command injection. The attack can be executed remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.6h