<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>MODSetter - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/modsetter/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 29 Sep 2026 04:24:40 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/modsetter/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Remote Command Injection in MODSetter SurfSense</title><link>https://feed.craftedsignal.io/briefs/2026-09-modsetter-surfsense-rce/</link><pubDate>Tue, 29 Sep 2026 04:24:40 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-modsetter-surfsense-rce/</guid><description>MODSetter SurfSense up to version 2.0.3 is vulnerable to remote command injection via the MCP Connector Integration component, allowing unauthenticated attackers to execute arbitrary system commands.</description><content:encoded><![CDATA[<p>A high-severity command injection vulnerability, identified as CVE-2026-102243, affects MODSetter SurfSense versions up to 2.0.3. The flaw resides within the MCP Connector Integration component, specifically within the /api/search-source/connectors/mcp/test endpoint. Remote attackers can leverage this unauthenticated endpoint to inject and execute arbitrary system commands on the underlying host. The vulnerability is confirmed to have publicly available exploit code, increasing the likelihood of exploitation. Despite early disclosure, the vendor has not provided a patch or formal response, leaving installations currently exposed. Defenders must prioritize restricting network access to the SurfSense application and monitoring for unusual process creation originating from the web server process.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation leads to full remote code execution on the server hosting SurfSense. Given that the MCP Connector Integration typically operates with elevated privileges to perform system connectivity tasks, this allows attackers to gain persistence, exfiltrate sensitive data, or move laterally within the internal network. No specific victim counts are available, but any internet-facing instance of SurfSense is considered at critical risk.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Monitor web server logs for suspicious requests targeting /api/search-source/connectors/mcp/test containing shell metacharacters.</li>
<li>Restrict network access to the SurfSense administration and integration endpoints to trusted internal IP addresses only.</li>
<li>Implement egress filtering on the server to prevent the application from making unauthorized outbound connections often used by reverse shells.</li>
<li>Since no patch is available, consider deploying a Web Application Firewall (WAF) rule to drop HTTP requests containing common shell command injection strings targeting this specific endpoint.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>web-application</category><category>authentication-bypass</category><category>cve-2026-102245</category></item></channel></rss>