OS Command Injection Vulnerability in Token Optimizer MCP by Ooples
CVE-2026-55157
8.4HIGH
What is CVE-2026-55157?
The Token Optimizer MCP tool, specifically the smart_user functionality, is vulnerable to OS command injection. This vulnerability allows any MCP client that calls the smart_user tool to execute arbitrary shell commands via the username argument in the get-user-info operation. Consequently, these commands run with the same privileges as the user operating the token-optimizer-mcp server. This issue has been resolved in version 5.1.0, emphasizing the importance of updating to mitigate risks.
Affected Version(s)
token-optimizer-mcp < 5.1.0
