Remote Code Execution Vulnerability in Code Runner MCP Server by Any Company
CVE-2026-5029
8.7HIGH
What is CVE-2026-5029?
A remote code execution vulnerability exists in Code Runner MCP Server when operating with the --transport http option, exposing the /mcp JSON-RPC endpoint without authentication on port 3088. This allows an unauthenticated remote attacker to invoke the run-code MCP tool, supplying arbitrary source code that can be executed via child_process.exec() using the designated language interpreter. Consequently, this grants the attacker the ability to run arbitrary code with the privileges of the user running the server. This issue has not been addressed and poses a risk across all versions of the product.
Affected Version(s)
Code Runner MCP Server 0
