CVE-2026-25905: mcp-run-python sandbox escape enables MCP server hijacking
Python code executed via 'runPython'/'runPythonAsync' in the mcp-run-python MCP server is not isolated from the surrounding JavaScript environment, letting Python code use Pyodide APIs to alter the JS environment. An attacker could hijack the MCP server, including shadowing MCP tools; the project is archived and unlikely to be fixed.
Disclosed 9 February 2026 · Record updated 13 September 2026
Impact
Attacker-supplied Python code can break out of the intended sandbox and take over the MCP server, enabling MCP tool shadowing; no fix expected as the project is archived.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-25905
