CVE-2026-44717: RCE in MCP Calculate Server via unsanitized eval()
MCP Calculate Server, an MCP-protocol mathematical calculation service built on SymPy, used eval() to evaluate expressions without input sanitization, allowing remote code execution. The issue was fixed in version 0.1.1.
Disclosed 15 May 2026 · Record updated 13 September 2026
Impact
Unsanitized input passed to eval() in versions prior to 0.1.1 allowed remote code execution on the host running the MCP server.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-44717
