Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

CVE-2026-44717: RCE in MCP Calculate Server via unsanitized eval()

MCP Calculate Server, an MCP-protocol mathematical calculation service built on SymPy, used eval() to evaluate expressions without input sanitization, allowing remote code execution. The issue was fixed in version 0.1.1.

Disclosed 15 May 2026 · Record updated 13 September 2026

Impact

Unsanitized input passed to eval() in versions prior to 0.1.1 allowed remote code execution on the host running the MCP server.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-44717