Multiple vulnerabilities have been identified in @ooples/token-optimizer-mcp, a package that allows for token optimization and management. The overall risk/impact is moderate to high due to potential OS command injection and unauthenticated path traversal attacks. Affected versions are not explicitly stated.
CVE-2026-55157 (CVSS 8.4 — High): An OS command injection vulnerability in @ooples/token-optimizer-mcp allows attackers to execute arbitrary local commands through the smart_user tool's get-user-info operation by injecting malicious payloads into the user-controlled username parameter.[/subscribe_to_unlock_form]
Multiple vulnerabilities have been identified in @ooples/token-optimizer-mcp, a package that allows for token optimization and management. The overall risk/impact is moderate to high due to potential OS command injection and unauthenticated path traversal attacks. Affected versions are not explicitly stated.
CVE-2026-55157 (CVSS 8.4 — High): An OS command injection vulnerability in @ooples/token-optimizer-mcp allows attackers to execute arbitrary local commands through the smart_user tool's get-user-info operation by injecting malicious payloads into the user-controlled username parameter.[emaillocker id="1283"]
CVE-2026-55156 (CVSS 5.3 — Medium): An unauthenticated attacker can perform path traversal attacks on the Dashboard Session Log API Endpoints, potentially leading to sensitive data exposure.
We recommend you to update @ooples/token-optimizer-mcp to version 5.7.0 or later.
The following reports contain further technical details:
[/emaillocker]