Deterministic Verification Gateway Vulnerability in QWED-MCP by QWED-AI
CVE-2026-55546
9.8CRITICAL
What is CVE-2026-55546?
The QWED-MCP is susceptible to a vulnerability where the verify_math_expression() function allows attacker-controlled expressions to be processed by SymPy's parse_expr() without sufficient validation or restriction of built-ins. This can lead to arbitrary command execution on the host system, exposing sensitive data and system resources. The vulnerability is mitigated in version 0.2.1, which restricts the execution context and enhances input validation.
Affected Version(s)
qwed-mcp < 0.2.1
