Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-30618: xszyou Fay 4.3.1 allows attackers to run unauthorized server commands

CVE-2026-30618 CVE-2026-30618
Summary

A publicly accessible management interface in xszyou Fay 4.3.1 can be exploited by an attacker to run unauthorized server commands. This allows the attacker to take control of the server, which could lead to data theft or disruption of service. Update to the latest version of xszyou Fay to fix this issue.

Original title
xszyou Fay 4.3.1 contains a remote code execution vulnerability in its MCP STDIO server management and command execution handling. A remote attacker can access the publicly exposed MCP management i...
Original description
xszyou Fay 4.3.1 contains a remote code execution vulnerability in its MCP STDIO server management and command execution handling. A remote attacker can access the publicly exposed MCP management interface and configure an MCP STDIO server with attacker-controlled commands and parameters, resulting in execution of arbitrary commands on the server. Successful exploitation allows arbitrary command execution within the context of the Fay service.
Vulnerability type
CWE-94 Code Injection
Published: 15 Jul 2026 · Updated: 17 Jul 2026 · First seen: 15 Jul 2026