Impact
The vulnerability is a command injection flaw in the getUsageByDateRange function of the Claude Usage Range Endpoint. By manipulating the argument-since parameter, an attacker can cause the server to execute arbitrary shell commands on the host. The impact includes compromised confidentiality, integrity, and availability on the affected system. The weakness is classified as CWE-74 and CWE-77.
Affected Systems
The affected product is abdullah1854's MCPGateway, up to commit 549f494a9e363f40530149de324b8097de424230. No further version details are available because the project uses continuous delivery with rolling releases, and the maintainers have not provided a fixed release. Any deployment of the current MCPGateway build that contains this function is vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, but the remote nature and publicly available exploit raise the risk beyond the base score. The EPSS score is not available, so the public exploit probability remains uncertain. The vulnerability is not listed in CISA's KEV catalog. It can be triggered remotely through the vulnerable endpoint, and a publicly available exploit is reported, meaning an attacker could leverage the flaw without needing privileged access to the application.
OpenCVE Enrichment