7MAPS

7Maps · News

Two MetaMCP flaws scored 9.8 and 9.1. The newest release is still 2.4.22.

By Lior AharonovFounder, 7IT Solutions ·

What happened

CVE records published on Tuesday, 29 September 2026 cover MetaMCP up to and including 2.4.22. CVE-2026-79538 (CVSS 9.8 per CISA) allows code execution through /mcp-proxy/server/stdio. CVE-2026-79537 (9.1) lets a caller use another tenant's session; the record says /metamcp/health/sessions hands out the session ids without authentication.

Why it matters

Your gateway sits in front of every tool your agents call. Traceforce, which found both flaws, lists container secrets and other tenants' data as exposed.

What to do

If you run MetaMCP, block /mcp-proxy/ at your reverse proxy, turn off open sign-up, keep it off the public internet and rotate the secrets in its environment.

A gateway is the one box that knows every key. Patch it like one, and when there is no patch, hide it like one.

Lior Aharonov · my take

Sources

securitygateways

Researched with AI tools; every fact is checked against the linked sources.

All 7Maps news · Atom feed

A correction: lior@7it.co.il. 7Maps by 7IT.