CVE-2026-44717

CRITICAL

MCP Calculate Server: Prompt Injection to RCE

Title source: cna
STIX 2.1

Description

MCP Calculate Server is a mathematical calculation service based on MCP protocol and SymPy library. Prior to 0.1.1, the use of eval() to evaluate mathematical expressions without proper input sanitization leads to remote code execution. This vulnerability is fixed in 0.1.1.

References (1)

Core 1

Scores

CVSS v3 9.8
EPSS 0.0048
EPSS Percentile 37.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-94
Status published
Products (1)
611711Dark/mcp_calculate_server < 0.1.1
Published May 15, 2026
Tracked Since May 15, 2026