Impact
The vulnerability resides in the PythonREPL.run function within the jij_mcp/python_repr.py module of the Jij‑MCP‑Server 0.1.0. By manipulating the code argument, an attacker can inject arbitrary Python code that is executed by the server. This results in remote code execution, potentially compromising confidentiality, integrity, and availability of the host running the server. The flaw stems from improper handling of user input and unsafe code evaluation, as classified by CWE‑74 and CWE‑94.
Affected Systems
The affected product is Jij‑MCP‑Server version 0.1.0 by Jij‑Inc. No other product versions or vendors are listed in the CNA data. Users running this version of the server should assume it is vulnerable until an official patch is released.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate risk. EPSS information is not available, but the exploit has been made public and can be launched remotely without prior authentication. The vulnerability is not included in the CISA KEV catalog, yet its public availability suggests that opportunistic exploitation may occur. Organizations should monitor for updates from Jij‑Inc and consider temporary containment measures while awaiting a formal fix.
OpenCVE Enrichment