天下漏洞,尽知其名
HIGH

CVE-2026-55157 Token Optimizer MCP 操作系统命令注入漏洞

影响攻击者可通过 MCP 客户端远程执行任意系统命令

AI 研判

token-optimizer-mcp 是一个用于统计 AI 编码代理 token 节省量、优化上下文并在 16 种 CLI 客户端间共享本地知识图谱的 MCP 服务。其 smart_user 工具的 get-user-info 操作在 5.1.0 之前版本存在 OS 命令注入漏洞,任何能调用该工具的 MCP 客户端均可注入并执行任意 shell 命令。

影响范围

token-optimizer-mcp

token-optimizer-mcp 5.1.0 之前的版本;5.1.0 已修复。

漏洞详情

漏洞类型为 OS 命令注入。smart_user 工具的 get-user-info 操作在处理 username 参数时未做充分过滤,直接将用户输入拼接进系统命令执行,导致攻击者可借助该参数注入并运行任意 shell 命令。命令以运行 token-optimizer-mcp 服务的用户权限执行。

利用条件与风险

利用前提是攻击者能够调用该 MCP 服务暴露的 smart_user 工具,通常需要能访问 MCP 客户端或服务接口。成功利用后可获得与服务进程相同权限的命令执行能力,实战风险较高。

修复建议

官方已在 5.1.0 版本中修复,建议升级至 5.1.0 或更高版本。临时缓解措施包括限制可调用 smart_user 工具的客户端、对 username 参数进行严格校验,以及以最小权限运行该 MCP 服务。

原始情报

Token Optimizer MCP measures token savings per AI coding agent, optimizes context, and shares a live local knowledge graph across 16 CLI clients. Prior to version 5.1.0, token-optimizer-mcp is vulnerable to OS command injection in the smart_user tool. Any MCP client that can call the smart_user tool can execute arbitrary shell commands through the username argument of the get-user-info operation. The commands execute with the privileges of the user running the token-optimizer-mcp server. This issue has been patched in version 5.1.0.