{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3amodsettersurfsense/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:modsetter:surfsense:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.4,"id":"CVE-2026-102243"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["SurfSense (\u003c= 2.0.3)"],"_cs_severities":["high"],"_cs_tags":["web-application","authentication-bypass","cve-2026-102245"],"_cs_type":"advisory","_cs_vendors":["MODSetter"],"content_html":"\u003cp\u003eA high-severity command injection vulnerability, identified as CVE-2026-102243, affects MODSetter SurfSense versions up to 2.0.3. The flaw resides within the MCP Connector Integration component, specifically within the /api/search-source/connectors/mcp/test endpoint. Remote attackers can leverage this unauthenticated endpoint to inject and execute arbitrary system commands on the underlying host. The vulnerability is confirmed to have publicly available exploit code, increasing the likelihood of exploitation. Despite early disclosure, the vendor has not provided a patch or formal response, leaving installations currently exposed. Defenders must prioritize restricting network access to the SurfSense application and monitoring for unusual process creation originating from the web server process.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation leads to full remote code execution on the server hosting SurfSense. Given that the MCP Connector Integration typically operates with elevated privileges to perform system connectivity tasks, this allows attackers to gain persistence, exfiltrate sensitive data, or move laterally within the internal network. No specific victim counts are available, but any internet-facing instance of SurfSense is considered at critical risk.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMonitor web server logs for suspicious requests targeting /api/search-source/connectors/mcp/test containing shell metacharacters.\u003c/li\u003e\n\u003cli\u003eRestrict network access to the SurfSense administration and integration endpoints to trusted internal IP addresses only.\u003c/li\u003e\n\u003cli\u003eImplement egress filtering on the server to prevent the application from making unauthorized outbound connections often used by reverse shells.\u003c/li\u003e\n\u003cli\u003eSince no patch is available, consider deploying a Web Application Firewall (WAF) rule to drop HTTP requests containing common shell command injection strings targeting this specific endpoint.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-29T04:24:56Z","date_published":"2026-09-29T04:24:40Z","id":"https://feed.craftedsignal.io/briefs/2026-09-modsetter-surfsense-rce/","summary":"MODSetter SurfSense up to version 2.0.3 is vulnerable to remote command injection via the MCP Connector Integration component, allowing unauthenticated attackers to execute arbitrary system commands.","title":"Remote Command Injection in MODSetter SurfSense","url":"https://feed.craftedsignal.io/briefs/2026-09-modsetter-surfsense-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:modsetter:surfsense:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}