Junglewise Threat Intelligence

CVE-2026-45555: MarcelRoozekrans Roslyn CodeLens MCP Server code injection in get_diagnostics

CVE-2026-45555 · Severity: high · CVSS 7.8 · Published 2026-05-29

Executive brief

The Roslyn CodeLens MCP Server, a tool used to provide code intelligence for .NET projects to AI assistants, contains a vulnerability that allows for arbitrary code execution. If a developer opens a malicious project file (such as one cloned from an untrusted source) using this server, the tool will automatically execute hidden malicious code embedded in the project. This could allow an attacker to steal sensitive data, access local files, or gain full control over the developer's workstation.

Technical details

A code injection vulnerability (CWE-94) exists in the Roslyn CodeLens MCP Server due to the insecure loading of Roslyn DiagnosticAnalyzers. The 'get_diagnostics' tool, by default, iterates through all 'AnalyzerReferences' in a target .csproj or .sln file and executes them via 'GetAnalyzerDiagnosticsAsync' without any allowlist, signature verification, or user confirmation. Because 'includeAnalyzers' defaults to true, an attacker can achieve arbitrary code execution in the context of the server process by tricking a user into opening a malicious project. The vulnerability is fixed in version 1.17.0 by requiring explicit opt-in for analyzer execution.

Affected products

  • MarcelRoozekrans Roslyn CodeLens MCP Server (RoslynCodeLens.Mcp) 0.0.9 to 1.17.0

Timeline

  • 2026-05-11: advisory: GitHub Security Advisory published by maintainer
  • 2026-05-29: disclosed: CVE published to NVD
  • 2026-05-29: patched: Fix released in version 1.17.0

References