---
id: CVE-2026-79537
title: >-
  metatool-ai MetaMCP through 2.4.22 contains an insecure direct object
  reference (IDOR) in the MCP transport session dispatch
summary: >-
  metatool-ai MetaMCP through 2.4.22 contains an insecure direct object
  reference (IDOR) in the MCP transport session dispatch. The session store
  (getSession in session-lifetime-manager.ts) is keyed only by the
  client-supplied mcp-session-…
severity: none
published: '2026-09-29'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T20:17:27.383'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-79537'
references:
  - url: 'https://github.com/metatool-ai/metamcp'
    label: cve@mitre.org
  - url: 'https://www.traceforce.ai/security-advisories/cve-2026-79537'
    label: cve@mitre.org
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-29T19:44:04.162Z'
---

## Overview

metatool-ai MetaMCP through 2.4.22 contains an insecure direct object reference (IDOR) in the MCP transport session dispatch. The session store (getSession in session-lifetime-manager.ts) is keyed only by the client-supplied mcp-session-id header with no owner, namespace, or endpoint binding, and the per-endpoint authorization middleware validates only the URL endpoint's owner, never the session. An attacker who supplies another tenant's session id " obtained without authentication from GET /metamcp/health/sessions, which discloses active session IDs and namespace UUIDs " can list and execute the victim tenant's private MCP tools and exfiltrate their data using the victim's forwarded credentials.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
