Two MetaMCP flaws scored 9.8 and 9.1. The newest release is still 2.4.22.
By Lior AharonovFounder, 7IT Solutions ·
CVE records published on Tuesday, 29 September 2026 cover MetaMCP up to and including 2.4.22. CVE-2026-79538 (CVSS 9.8 per CISA) allows code execution through /mcp-proxy/server/stdio. CVE-2026-79537 (9.1) lets a caller use another tenant's session; the record says /metamcp/health/sessions hands out the session ids without authentication.
Your gateway sits in front of every tool your agents call. Traceforce, which found both flaws, lists container secrets and other tenants' data as exposed.
If you run MetaMCP, block /mcp-proxy/ at your reverse proxy, turn off open sign-up, keep it off the public internet and rotate the secrets in its environment.
A gateway is the one box that knows every key. Patch it like one, and when there is no patch, hide it like one.
Lior Aharonov · my takeSources
- CVE-2026-79538 (CVE Program) cve.org
- CVE-2026-79537 record (CVE Program) cveawg.mitre.org
- CVE-2026-79537 advisory (Traceforce) traceforce.ai
- CVE-2026-79538 advisory (Traceforce) traceforce.ai
- MetaMCP releases (GitHub) github.com
Researched with AI tools; every fact is checked against the linked sources.