OS Command Injection Vulnerability in Token Optimizer MCP by Ooples
CVE-2026-55157

8.4HIGH

Key Information:

Vendor

Ooples

Vendor
CVE Published:
28 September 2026

What is CVE-2026-55157?

The Token Optimizer MCP tool, specifically the smart_user functionality, is vulnerable to OS command injection. This vulnerability allows any MCP client that calls the smart_user tool to execute arbitrary shell commands via the username argument in the get-user-info operation. Consequently, these commands run with the same privileges as the user operating the token-optimizer-mcp server. This issue has been resolved in version 5.1.0, emphasizing the importance of updating to mitigate risks.

Affected Version(s)

token-optimizer-mcp < 5.1.0

References

CVSS V3.1

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.