CVE-2026-44717 – MCP Calculate Server: Prompt Injection to RCE

​CVE ID :CVE-2026-44717

Published : May 15, 2026, 5:16 p.m. | 1 hour, 17 minutes ago

Description :MCP Calculate Server is a mathematical calculation service based on MCP protocol and SymPy library. Prior to 0.1.1, the use of eval() to evaluate mathematical expressions without proper input sanitization leads to remote code execution. This vulnerability is fixed in 0.1.1.

Severity: 9.8 | CRITICAL

Visit the link for more details, such as CVSS details, affected products, timeline, and more… To Read More Visit Read More