Executive brief
xszyou Fay, an agent framework used to connect digital humans and large language models to business systems, contains a critical security flaw. An attacker can remotely access the management interface to inject and execute malicious commands on the underlying server. This could lead to a total system takeover, unauthorized data access, or disruption of the digital human services.
Technical details
A remote code execution (RCE) vulnerability exists in xszyou Fay version 4.3.1 due to improper validation of commands within the Model Context Protocol (MCP) STDIO server management interface. The vulnerability stems from a systemic command injection issue in the implementation of Anthropic's MCP SDK. A remote, unauthenticated attacker can reach the exposed MCP management interface and configure a new STDIO server with arbitrary commands and parameters. When the Fay service attempts to manage or execute these configured commands, it triggers the execution of attacker-controlled code within the context of the Fay service. This allows for complete compromise of the host environment.
Affected products
- xszyou Fay 4.3.1
Timeline
- 2026-04-15: disclosed: OX Security researchers identified the systemic MCP command injection vulnerability.
- 2026-07-15: advisory: CVE-2026-30618 published to the NVD.