CVE-2026-30618

CRITICAL

Fay 4.3.1 - Remote Code Execution via MCP STDIO Server Command Injection

Title source: llm
STIX 2.1

Description

xszyou Fay 4.3.1 contains a remote code execution vulnerability in its MCP STDIO server management and command execution handling. A remote attacker can access the publicly exposed MCP management interface and configure an MCP STDIO server with attacker-controlled commands and parameters, resulting in execution of arbitrary commands on the server. Successful exploitation allows arbitrary command execution within the context of the Fay service.

Scores

CVSS v3 9.8
EPSS 0.0167
EPSS Percentile 74.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-94
Status published
Published Jul 15, 2026
Tracked Since Jul 16, 2026