Remote Code Execution Vulnerability in Code Runner MCP Server by Any Company
CVE-2026-5029

8.7HIGH

Key Information:

Vendor
CVE Published:
12 May 2026

What is CVE-2026-5029?

A remote code execution vulnerability exists in Code Runner MCP Server when operating with the --transport http option, exposing the /mcp JSON-RPC endpoint without authentication on port 3088. This allows an unauthenticated remote attacker to invoke the run-code MCP tool, supplying arbitrary source code that can be executed via child_process.exec() using the designated language interpreter. Consequently, this grants the attacker the ability to run arbitrary code with the privileges of the user running the server. This issue has not been addressed and poses a risk across all versions of the product.

Affected Version(s)

Code Runner MCP Server 0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Eryk Winiarz
.