@ooples/token-optimizer-mcp vulnerabilities
CVEs whose affected-version data names the @ooples/token-optimizer-mcp package (npm). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-55157High· 8.4Token Optimizer MCP: OS command injection in smart_user via username in get-user-info
Token Optimizer MCP: OS command injection in smart_user via username in get-user-info
▾ Twilightooples · @ooples/token-optimizer-mcpvia GHSA
CVE-2026-55156Medium· 5.3Token Optimizer MCP: Unauthenticated Path Traversal in Dashboard Session Log API Endpoints
Token Optimizer MCP: Unauthenticated Path Traversal in Dashboard Session Log API Endpoints
▾ Sunlitooples · @ooples/token-optimizer-mcpvia GHSA