PT-2026-39994 · Code Runner Mcp Server · Code Runner Mcp Server

Eryk Winiarz

·

Published

2026-05-12

·

Updated

2026-05-12

·

CVE-2026-5029

CVSS v4.0

8.7

High

VectorAV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
A remote code execution vulnerability exists in Code Runner MCP Server when run with the --transport http option, which exposes the /mcp JSON-RPC endpoint without authentication on port 3088. An unauthenticated remote attacker can invoke the run-code MCP tool to supply arbitrary source code and execute it via child process.exec() using the specified language interpreter. This allows execution of arbitrary code with the privileges of the user running the server. This vulnerability has not been fixed and might affect the project in all versions.

Fix

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2026-5029

Affected Products

Code Runner Mcp Server