CVE-2026-30618

xszyou Fay 4.3.1 contains a remote code execution vulnerability in its MCP STDIO server management and command execution handling. A remote attacker can access the publicly exposed MCP management interface and configure an MCP STDIO server with attacker-controlled commands and parameters, resulting in execution of arbitrary commands on the server. Successful exploitation allows arbitrary command execution within the context of the Fay service.
Configurations

No configuration.

History

16 Jul 2026, 14:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE CWE-94

15 Jul 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-15 22:16

Updated : 2026-07-16 14:16


NVD link : CVE-2026-30618

Mitre link : CVE-2026-30618

CVE.ORG link : CVE-2026-30618


JSON object : View

Products Affected

No product.

CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')