CVE 9.8 CRITICAL

MCP Calculate Server: Prompt Injection to RCE_CVE-2026-44717

9.8 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

MCP Calculate Server is a mathematical calculation service based on MCP protocol and SymPy library. Prior to 0.1.1, the use of eval() to evaluate mathematical expressions without proper input sanitization leads to remote code execution. This vulnerability is fixed in 0.1.1.

AI Analysis

Remote code execution vulnerability due to improper input sanitization in mathematical expressions

Basic Information

ID CVE-2026-44717
Source GitHub_M
Published May 15, 2026 at 16:58

Affected Product

Vendor 611711Dark
Product mcp_calculate_server
Version < 0.1.1
Affected Versions 611711Dark mcp_calculate_server < 0.1.1

CWE Classification

AI Assessment

AI Score 9.8 / 10
AI Severity Critical
Vendor 611711Dark
Product MCP Calculate Server
Version < 0.1.1

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.