Impact
The xszyou Fay application, version 4.3.1, contains a command injection flaw in its MCP STDIO server management component, classified as CWE‑94. An attacker that can reach the publicly exposed MCP management interface can instruct the server to execute arbitrary commands, resulting in code execution within the context of the running Fay service. This provides an attacker with full control over the service’s privileges, causing loss of confidentiality, integrity, and availability.
Affected Systems
The sole affected product is xszyou Fay 4.3.1. No other vendors or product versions are listed as affected. The vulnerability is specific to the MCP STDIO server management functionality within this version.
Risk and Exploitability
With a CVSS score of 9.8, this vulnerability is rated critical. The EPSS score of 2% indicates a non‑negligible likelihood of exploitation. The flaw is not listed in the CISA KEV catalog. A network‑based attacker who can reach the MCP management interface can send crafted requests to the server and achieve arbitrary code execution in the Fay service’s context.
OpenCVE Enrichment