9.8
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
MCP Calculate Server is a mathematical calculation service based on MCP protocol and SymPy library. Prior to 0.1.1, the use of eval() to evaluate mathematical expressions without proper input sanitization leads to remote code execution. This vulnerability is fixed in 0.1.1.
AI Analysis
Remote code execution vulnerability due to improper input sanitization in mathematical expressions
Basic Information
ID
CVE-2026-44717
Source
GitHub_M
Published
May 15, 2026 at 16:58
Affected Product
Vendor
611711Dark
Product
mcp_calculate_server
Version
< 0.1.1
Affected Versions
611711Dark mcp_calculate_server < 0.1.1
CWE Classification
AI Assessment
AI Score
9.8 / 10
AI Severity
Critical
Vendor
611711Dark
Product
MCP Calculate Server
Version
< 0.1.1