CVE-2026-102243
Received Received - Intake

Command Injection in MODSetter SurfSense

Vulnerability report for CVE-2026-102243, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: VulDB

Description

A vulnerability was identified in MODSetter SurfSense up to 2.0.3. This issue affects some unknown processing of the file /api/search-source/connectors/mcp/test of the component MCP Connector Integration. Such manipulation leads to command injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
modsetter surfsense to 2.0.3 (inc)
modsetter surfsense 0.0.36

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-74 The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
CWE-77 The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an authenticated OS command injection vulnerability in SurfSense version 0.0.36. It exists in the FastAPI backend's MCP connector management, specifically in the /api/v1/connectors/mcp/test endpoint. Any authenticated user can pass arbitrary commands, arguments, and environment variables to this endpoint, which the backend executes with stdio MCP transport without any command allowlist.

Detection Guidance

Check for SurfSense versions up to 2.0.3 or 0.0.36 by inspecting running containers or application logs. Look for suspicious activity in the /api/search-source/connectors/mcp/test or /api/v1/connectors/mcp/test endpoints, such as unusual command execution patterns or unauthorized access attempts.

Impact Analysis

The vulnerability allows remote attackers to execute arbitrary OS commands as root within the backend container, potentially leading to full system compromise. The official Docker image runs the process as root, inheriting sensitive environment variables like SECRET_KEY, database URLs, and API keys.

Compliance Impact

This vulnerability allows remote attackers to execute arbitrary OS commands as root within the backend container, potentially leading to full system compromise. This could result in unauthorized access to sensitive data, including personal or health information, which would violate GDPR and HIPAA compliance requirements for data protection and confidentiality.

Mitigation Strategies

Disable stdio MCP transport in SurfSense, implement strict command allowlists for the vulnerable endpoints, remove user-supplied environment variables from the MCP connector integration, and enforce least-privilege workspace permissions. Ensure the application runs with minimal required privileges instead of root.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102243. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart