Description
xszyou Fay 4.3.1 contains a remote code execution vulnerability in its MCP STDIO server management and command execution handling. A remote attacker can access the publicly exposed MCP management interface and configure an MCP STDIO server with attacker-controlled commands and parameters, resulting in execution of arbitrary commands on the server. Successful exploitation allows arbitrary command execution within the context of the Fay service.
Published: 2026-07-15
Score: 9.8 Critical
EPSS: 1.7% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The xszyou Fay application, version 4.3.1, contains a command injection flaw in its MCP STDIO server management component, classified as CWE‑94. An attacker that can reach the publicly exposed MCP management interface can instruct the server to execute arbitrary commands, resulting in code execution within the context of the running Fay service. This provides an attacker with full control over the service’s privileges, causing loss of confidentiality, integrity, and availability.

Affected Systems

The sole affected product is xszyou Fay 4.3.1. No other vendors or product versions are listed as affected. The vulnerability is specific to the MCP STDIO server management functionality within this version.

Risk and Exploitability

With a CVSS score of 9.8, this vulnerability is rated critical. The EPSS score of 2% indicates a non‑negligible likelihood of exploitation. The flaw is not listed in the CISA KEV catalog. A network‑based attacker who can reach the MCP management interface can send crafted requests to the server and achieve arbitrary code execution in the Fay service’s context.

Generated by OpenCVE AI on August 1, 2026 at 09:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest update to xszyou Fay that resolves the MCP STDIO command injection flaw.
  • Restrict inbound traffic to the MCP management interface so that only authorized IP ranges can reach the API.
  • If the MCP STDIO server is not required for your deployment, disable the component entirely to remove the vulnerable service.

Generated by OpenCVE AI on August 1, 2026 at 09:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 01 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via MCP STDIO Command Injection in xszyou Fay 4.3.1

Tue, 28 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via MCP STDIO Command Injection in xszyou Fay 4.3.1

Sun, 26 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via MCP STDIO in xszyou Fay 4.3.1

Wed, 22 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via MCP STDIO in xszyou Fay 4.3.1

Thu, 16 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-94
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 15 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description xszyou Fay 4.3.1 contains a remote code execution vulnerability in its MCP STDIO server management and command execution handling. A remote attacker can access the publicly exposed MCP management interface and configure an MCP STDIO server with attacker-controlled commands and parameters, resulting in execution of arbitrary commands on the server. Successful exploitation allows arbitrary command execution within the context of the Fay service.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-16T13:24:00.406Z

Reserved: 2026-03-04T00:00:00.000Z

Link: CVE-2026-30618

cve-icon Vulnrichment

Updated: 2026-07-16T13:23:55.345Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T09:15:03Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')