QWED-MCP is a deterministic verification gateway for MCP. Prior to 0.2.1, verifymathexpression() in src/qwedmcp/engines/mathengine.py passes attacker-controlled expression and claimedresult strings directly to SymPy's parseexpr() after only normalizing caret syntax to Python exponent syntax, without restricting globaldict, removing Python built-ins, or validating the expression AST. Because parseexpr() calls Python's eval() with built-ins available, an attacker who can cause a downstream caller to pass untrusted input to this public library function can use Python import functionality to execute arbitrary operating-system commands as the qwed-mcp process user, read or modify accessible data, exfiltrate process secrets, or reach internal services. The default MCP tool registry does not expose verifymathexpression(), so exploitation requires a downstream integration that invokes the library API with attacker-controlled input. This issue is fixed in version 0.2.1.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55546.json",
"cwe_ids": [
"CWE-94"
],
"cna_assigner": "GitHub_M"
}