Skip to content
Threat Feed
high advisory

Remote Command Injection in MODSetter SurfSense

MODSetter SurfSense up to version 2.0.3 is vulnerable to remote command injection via the MCP Connector Integration component, allowing unauthenticated attackers to execute arbitrary system commands.

CVE search metadata

CVE search record: CVE-2026-102243. Severity: high. CVSS: 7.4. KEV: no. Product: SurfSense (<= 2.0.3). Brief: Remote Command Injection in MODSetter SurfSense. Brief link: https://feed.craftedsignal.io/briefs/2026-09-modsetter-surfsense-rce/

What's new

  • 1. added coverage for SurfSense (<= 2.0.3) Sep 29, 04:24 via nvd

A high-severity command injection vulnerability, identified as CVE-2026-102243, affects MODSetter SurfSense versions up to 2.0.3. The flaw resides within the MCP Connector Integration component, specifically within the /api/search-source/connectors/mcp/test endpoint. Remote attackers can leverage this unauthenticated endpoint to inject and execute arbitrary system commands on the underlying host. The vulnerability is confirmed to have publicly available exploit code, increasing the likelihood of exploitation. Despite early disclosure, the vendor has not provided a patch or formal response, leaving installations currently exposed. Defenders must prioritize restricting network access to the SurfSense application and monitoring for unusual process creation originating from the web server process.

Impact

Successful exploitation leads to full remote code execution on the server hosting SurfSense. Given that the MCP Connector Integration typically operates with elevated privileges to perform system connectivity tasks, this allows attackers to gain persistence, exfiltrate sensitive data, or move laterally within the internal network. No specific victim counts are available, but any internet-facing instance of SurfSense is considered at critical risk.

Recommendation

  • Monitor web server logs for suspicious requests targeting /api/search-source/connectors/mcp/test containing shell metacharacters.
  • Restrict network access to the SurfSense administration and integration endpoints to trusted internal IP addresses only.
  • Implement egress filtering on the server to prevent the application from making unauthorized outbound connections often used by reverse shells.
  • Since no patch is available, consider deploying a Web Application Firewall (WAF) rule to drop HTTP requests containing common shell command injection strings targeting this specific endpoint.

Immediate actions

Deploy the provided WAF/web-server rule for CVE-2026-102243

SOC 24h

Mitigations

Restrict external network access to the MCP Connector endpoint

immediate IT Operations

CVE-2026-102243

Detection coverage 1

Detect CVE-2026-102243 Exploitation - Command Injection via MCP Connector

high

Detects exploitation attempts against CVE-2026-102243 where an attacker sends a POST request with shell metacharacters to the vulnerable test endpoint.

sigma tactics: execution, initial_access techniques: T1190 sources: webserver

Detection queries are available on the platform. Get full rules →