CyberRota Analysis
AI-GeneratedThe vulnerability affects the MetaMCP component of metatool-ai versions up to 2.4.22, where an insecure direct object reference (IDOR) allows attackers to exploit session IDs obtained from an unauthenticated endpoint. This flaw enables unauthorized access to private tools and data belonging to other tenants, as the session management lacks proper authorization checks. Organizations using this software, particularly those managing multiple tenants, should prioritize addressing this vulnerability to prevent potential data breaches and unauthorized access.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
metatool-ai MetaMCP through 2.4.22 contains an insecure direct object reference (IDOR) in the MCP transport session dispatch. The session store (getSession in session-lifetime-manager.ts) is keyed only by the client-supplied mcp-session-id header with no owner, namespace, or endpoint binding, and the per-endpoint authorization middleware validates only the URL endpoint's owner, never the session. An attacker who supplies another tenant's session id " obtained without authentication from GET /metamcp/health/sessions, which discloses active session IDs and namespace UUIDs " can list and execute the victim tenant's private MCP tools and exfiltrate their data using the victim's forwarded credentials.