Sceawere
Vulnerability Detail
CVE-2026-105797UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
SimpleChat Authorization Bypass Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.8
- Creation Date
- 10h ago
- Vendor
- microsoft
- Product
- simplechat
- Attack Type
- CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions. In versions 0.261.003 and 0.261.027, an authorization ordering flaw in POST /api/user/plugins allows an authenticated low-privileged user to omit the top-level MCP type so that _reject_non_admin_mcp_stdio skips inspection before the type is restored from metadata. The stored personal action can then reach McpPluginFactory.create_connector, and MCPStdioPlugin.connect starts the attacker-selected operating-system process under the application service identity when the action tool is invoked. Exploitation requires personal plugins to be enabled and governance to permit MCP actions, and it can expose or modify secrets and data available to the service or disrupt the service. This issue is fixed in version 0.261.031.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.8",
"pubDate": "2026-10-06T15:17:16.733Z",
"pubdate": "2026-10-06T15:17:16.733Z",
"executiveSummary": "SimpleChat versions 0.261.003 and 0.261.027 contain a critical authorization ordering flaw within the POST /api/user/plugins endpoint, classified as an Improper Authorization vulnerability.\nThe flaw permits an authenticated, low-privileged user to bypass security enforcement mechanisms, specifically the _reject_non_admin_mcp_stdio inspection process.\nBy manipulating the top-level MCP (Model Context Protocol) type field in the API request, an attacker can successfully register unauthorized personal plugins.\nSuccessful exploitation results in arbitrary operating-system process execution under the context of the application service identity, facilitating potential remote code execution (RCE).\nThe vulnerability requires that personal plugins are enabled within the environment and that governance policies explicitly permit MCP actions.\nImpact includes the exposure or unauthorized modification of sensitive system data, credential theft, and significant service disruption.\nRisk is categorized as high, as it allows a low-privileged user to elevate their capabilities to perform unauthorized actions at the system level.",
"technicalDetails": "The vulnerability originates from a logical flaw in the authorization middleware and input processing pipeline within the POST /api/user/plugins endpoint.\nWhen a user submits a plugin configuration, the application attempts to validate the request using the _reject_non_admin_mcp_stdio function. This function is designed to prevent non-administrative users from defining MCP Stdio plugins.\nThe root cause is an insecure ordering of operations: the application allows the omission of the top-level MCP type during the initial validation check. By omitting this field, the payload bypasses the _reject_non_admin_mcp_stdio inspection logic entirely.\nFollowing the validation check, the application restores the MCP type from metadata, effectively re-injecting the malicious configuration into the object state before it is persisted.\nThe stored personal action is then processed by the McpPluginFactory.create_connector method. Because the validation check was circumvented, the factory treats the malicious configuration as legitimate, creating an instance of MCPStdioPlugin.\nThe exploit proceeds as follows: 1. The attacker crafts a request to POST /api/user/plugins with the top-level MCP type stripped or missing. 2. The middleware skips the security check because it does not identify the payload as a restricted MCP Stdio type. 3. The application restores the payload's metadata, re-applying the MCP Stdio type. 4. The malicious configuration is saved to the user's personal plugin store. 5. Upon invocation of the tool via the AI interface, the MCPStdioPlugin.connect method is triggered.\nThe MCPStdioPlugin.connect method initiates the attacker-defined operating-system process. Since the process is spawned under the security context of the SimpleChat application service identity, the attacker inherits the service's system-level permissions.\nThis allows the execution of arbitrary commands, facilitating post-exploitation activities such as reading environment variables (containing secrets), modifying system configurations, or interacting with internal APIs that the service is authorized to access.\nThe issue is confirmed in versions 0.261.003 and 0.261.027 and requires an authenticated session with sufficient permissions to access the plugin registration API."
}