qwed-mcp has Unsafe SymPy `parse_expr()` Remote Code Execution via Unsanitized Math Expression Input
Unauthenticated input can trigger arbitrary OS command execution, potentially giving full control of the running qwed-mcp process.

2 CRIT · 13 HIGH · 1 MED · THREAT RED · 16 items · Generated in 310s
Unauthenticated input can trigger arbitrary OS command execution, potentially giving full control of the running qwed-mcp process.
If MCP is enabled, any client can hit /mcp and run shell commands as the Chainlit process without authentication.
A malicious site can send unauthenticated requests to the local MCP server and make it execute actions in the victim's browser session.
Unauthenticated SSRF can reach internal services or cloud metadata and send attacker-chosen headers.
A malicious MCP caller or injected agent flow can write attacker-controlled files anywhere the process can reach, leading to host code execution.
Default unauthenticated webhook lets anyone delete or corrupt vector data for any user.
Anyone who can reach the MCP endpoint can start a session, list tools, and trigger server-side actions using the host's configured API key.
An attacker who can call the MCP tool can overwrite server-accessible files, risking service damage and unauthorized access.
A malicious webpage can reach a local MCP server and run tools without auth when the default no-API-key setup is used.
Anyone who can reach the endpoint can trigger unbounded memory growth and crash the service.
Unauthenticated requests can bypass decode limits and exhaust GPU video resources, degrading or denying service for other users.
A user who can edit prompt templates can run arbitrary code on the gateway host and take over the service account.
Unauthenticated access to a local model server can let attackers poison agents and persistently corrupt AI behavior.
Opening a crafted notebook in edit mode could run attacker-supplied local commands before normal cell execution.
Illegal AI server exports raise supply and compliance risk around restricted compute and chip distribution.
Developers searching for Codex can be tricked into installing Mac malware from fake ads, turning normal tool discovery into compromise.