| CVE ID | CVE-2026-5029 |
| Publication date | 12 May 2026 |
| Vendor | Code Runner MCP Server |
| Product | Code Runner MCP Server |
| Vulnerable versions | All |
| Vulnerability type (CWE) | Missing Authentication for Critical Function (CWE-306) |
| Report source | Report to CERT Polska |
Description
CERT Polska has received a report about vulnerability in Code Runner MCP Server software and participated in coordination of its disclosure.
The vulnerability CVE-2026-5029: A remote code execution vulnerability exists in Code Runner MCP Server when run with the --transport http option, which exposes the /mcp JSON-RPC endpoint without authentication on port 3088. An unauthenticated remote attacker can invoke the run-code MCP tool to supply arbitrary source code and execute it via child_process.exec() using the specified language interpreter. This allows execution of arbitrary code with the privileges of the user running the server.
This vulnerability has not been fixed and might affect the project in all versions.
Credits
We thank Eryk Winiarz for the responsible vulnerability report.
More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.