PT-2026-44846 · Marcelroozekrans · Roslyn-Codelens-Mcp
232-323
+1
·
Published
2026-05-29
·
Updated
2026-06-09
·
CVE-2026-45555
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Roslyn CodeLens MCP Server versions 0.0.9 through 1.16.0
Description
The
get diagnostics MCP tool loads and executes all DiagnosticAnalyzer assemblies referenced by the target solution without an allowlist, signature check, or user confirmation. Because the includeAnalyzers variable defaults to true, no explicit opt-in is required. An attacker can achieve arbitrary code execution in the server process with the server's OS privileges by placing a malicious .csproj file that references an attacker-controlled DLL in a location opened by the victim using the MCP server.Recommendations
Update to version 1.17.0.
Exploit
Fix
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Roslyn-Codelens-Mcp