Sceawere
Vulnerability Detail
CVE-2026-102243UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
MODSetter SurfSense Command Injection
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.4
- Creation Date
- 4h ago
- Vendor
- MODSetter
- Product
- SurfSense
- Attack Type
- Command Injection
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was identified in MODSetter SurfSense up to 2.0.3. This issue affects some unknown processing of the file /api/search-source/connectors/mcp/test of the component MCP Connector Integration. Such manipulation leads to command injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.4",
"pubDate": "2026-09-29T03:17:15.730Z",
"pubdate": "2026-09-29T03:17:15.730Z",
"executiveSummary": "A critical command injection vulnerability exists within the MCP Connector Integration component of MODSetter SurfSense, affecting versions up to 2.0.3.\nThe vulnerability resides in the processing logic of the /api/search-source/connectors/mcp/test endpoint, allowing unauthenticated remote attackers to execute arbitrary system commands with the privileges of the underlying application service.\nThis flaw presents a severe security risk, as it facilitates remote code execution (RCE), potentially leading to complete system compromise, unauthorized data exfiltration, and lateral movement within the network.\nThe attack vector is remotely exploitable, and the availability of public exploits significantly increases the likelihood of malicious exploitation.\nGiven that the vendor has been non-responsive regarding this disclosure, the risk remains unmitigated for all deployments running the affected versions.",
"technicalDetails": "The vulnerability is a command injection flaw located within the MCP Connector Integration component of the MODSetter SurfSense application. Specifically, the processing logic associated with the /api/search-source/connectors/mcp/test endpoint fails to adequately sanitize user-supplied input before passing it to an underlying system shell or execution environment.\nThe root cause of this vulnerability is the insecure implementation of backend process invocation. When the application interacts with the MCP Connector, it processes parameters sent to the /api/search-source/connectors/mcp/test endpoint. If these parameters are concatenated directly into a system command string without appropriate validation or escaping, an attacker can append malicious shell metacharacters (such as ';', '&', '|', or '`') to inject and execute arbitrary commands.\nThe attack flow proceeds as follows: 1. An attacker identifies the target endpoint /api/search-source/connectors/mcp/test. 2. The attacker crafts a malicious HTTP request containing a payload designed to terminate the intended command and initiate a secondary, unauthorized command. 3. The server-side application processes the malicious input and executes the injected payload within the context of the application's process. 4. The system executes the attacker-defined commands, granting the attacker the ability to perform reconnaissance, install persistent backdoors, or manipulate system files.\nThis vulnerability is classified as remotely exploitable, requiring no prior authentication. The lack of input validation and the direct execution of system-level commands indicate a fundamental flaw in the application's design regarding interaction with the operating system. Because the MCP Connector Integration component runs with specific system privileges, successful exploitation allows the attacker to operate within that security context, effectively bypassing application-level access controls.\nThe exploitability is heightened by the availability of public proof-of-concept code, which lowers the barrier to entry for potential attackers. Post-exploitation impact includes full system control, potential access to sensitive internal configuration files, environment variables containing credentials, and the ability to leverage the compromised node to attack other internal assets within the network architecture. Since the vendor has not provided a patch, the threat remains persistent for all instances running version 2.0.3 or earlier."
}