Deterministic Verification Gateway Vulnerability in QWED-MCP by QWED-AI
CVE-2026-55546

9.8CRITICAL

Key Information:

Vendor

Qwed-ai

Status
Vendor
CVE Published:
25 August 2026

What is CVE-2026-55546?

The QWED-MCP is susceptible to a vulnerability where the verify_math_expression() function allows attacker-controlled expressions to be processed by SymPy's parse_expr() without sufficient validation or restriction of built-ins. This can lead to arbitrary command execution on the host system, exposing sensitive data and system resources. The vulnerability is mitigated in version 0.2.1, which restricts the execution context and enhances input validation.

Affected Version(s)

qwed-mcp < 0.2.1

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.