CVE-2026-5029 | Code Runner MCP Server RPC Endpoint /mcp child_process.exec missing authentication
A vulnerability classified as critical was found in Code Runner MCP Server. Affected by this vulnerability is the function child_process.exec of the file /mcp of the component RPC Endpoint. Such manipulation leads to missing authentication.
This vulnerability is listed as CVE-2026-5029. The attack must be carried out from within the local network. There is no available exploit.