Executive brief
Jij-MCP-Server is a Model Context Protocol server used for mathematical optimization and quantum computing tasks. It contains a remote code execution vulnerability in the jm_check tool that allows attackers to execute arbitrary Python code and operating system commands by passing malicious code strings to a validation function. An attacker with access to the MCP server—either directly or through prompt injection of an AI client—can gain full control of the host system running the server.
Technical details
The vulnerability is a code injection flaw in the PythonREPL.run() method in jij_mcp/python_repr.py. The jm_check tool accepts a user-controlled code parameter and passes it directly to Python's exec() function without sandboxing, restricted builtins, or subprocess isolation. The only guard is a basic detection of Python for-loops, which can be trivially bypassed with one-liner payloads (e.g., import os; os.system("calc")). The attack vector is network-accessible via MCP protocol calls, requiring no authentication. An attacker can achieve arbitrary code execution under the privileges of the MCP server process. The vulnerability affects version 0.1.0, and the developers have not yet responded to the disclosure.
Affected products
- Jij-Inc Jij-MCP-Server 0.1.0
Timeline
- 2026-06-29: disclosed: Vulnerability disclosed via GitHub issue #4
- 2026-08-17: advisory: Published to NVD as CVE-2026-19964
- 2026-06-29: other: Public exploit demonstration available