Threat Advisory

Token Optimizer MCP Vulnerabilities Impact JSONL Runtime Log Entries

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple vulnerabilities have been identified in @ooples/token-optimizer-mcp, a package that allows for token optimization and management. The overall risk/impact is moderate to high due to potential OS command injection and unauthenticated path traversal attacks. Affected versions are not explicitly stated.

CVE-2026-55157 (CVSS 8.4 — High): An OS command injection vulnerability in @ooples/token-optimizer-mcp allows attackers to execute arbitrary local commands through the smart_user tool's get-user-info operation by injecting malicious payloads into the user-controlled username parameter.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple vulnerabilities have been identified in @ooples/token-optimizer-mcp, a package that allows for token optimization and management. The overall risk/impact is moderate to high due to potential OS command injection and unauthenticated path traversal attacks. Affected versions are not explicitly stated.

CVE-2026-55157 (CVSS 8.4 — High): An OS command injection vulnerability in @ooples/token-optimizer-mcp allows attackers to execute arbitrary local commands through the smart_user tool's get-user-info operation by injecting malicious payloads into the user-controlled username parameter.[emaillocker id="1283"]

CVE-2026-55156 (CVSS 5.3 — Medium): An unauthenticated attacker can perform path traversal attacks on the Dashboard Session Log API Endpoints, potentially leading to sensitive data exposure.

RECOMMENDATION:

We recommend you to update @ooples/token-optimizer-mcp to version 5.7.0 or later.

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu