Impact
Metatool‑ai MetaMCP versions up to 2.4.22 implement an insecure direct object reference. The session store uses a client‑supplied request header to identify sessions but does not bind the session to the tenant, namespace or request endpoint. Based on the description, the attacker can obtain a valid session ID belonging to another tenant. This ID can be discovered by querying the publicly accessible /metamcp/health/sessions endpoint, which exposes active session IDs and namespace UUIDs. With that session ID the attacker may list and invoke tenant‑specific MCP tools and exfiltrate data using the victim’s forwarded credentials, thereby compromising confidentiality and integrity of the victim tenant’s data.
Affected Systems
The affected product is Metatool‑ai MetaMCP 2.4.22 and all earlier releases. Any deployment that has not been upgraded beyond this version is vulnerable.
Risk and Exploitability
The vulnerability is highly exploitable because the session ID is transmitted in a header with no per‑tenant binding or endpoint validation. An attacker who can read the health endpoint requires no authentication, which is typically exposed to untrusted networks. The EPSS score is not available and the flaw is not yet listed in the CISA KEV catalog. Given the lack of protections, the likelihood of exploitation is significant in environments where MetaMCP is reachable from the public internet.
OpenCVE Enrichment