PT-2026-36605 · 8Nite · Metatrader-4-Mcp

Brucejqs

·

Published

2026-05-02

·

Updated

2026-05-02

·

CVE-2026-7627

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
A security vulnerability has been detected in 8nite metatrader-4-mcp 1.0.0. This vulnerability affects the function CallToolRequestSchema of the file src/index.ts of the component sync ea from file. Such manipulation of the argument ea name leads to path traversal. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2026-7627

Affected Products

Metatrader-4-Mcp