Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacyΒ© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
mcpjam-to-root β€” From MCPJam Inspector RCE to root β€” CVE-2026-23744, JupyterLab token disclosure, kernel execution, and OPSMCP privilege escalation | Kitploit
Tools/GitHubGitHub/itsc1sco/mcpjam-to-root
Privilege EscalationVulnerability AnalysisExploitationWeb Application ExploitationPost-ExploitationPenetration TestingLearning & EducationAPI Security
GitHubitsc1sco/mcpjam-to-root

mcpjam-to-root

From MCPJam Inspector RCE to root β€” CVE-2026-23744, JupyterLab token disclosure, kernel execution, and OPSMCP privilege escalation

171 month agoNot yet reviewed

Most Popular

View all β†’

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools β†’
Share
View Repository

⚠️ Disclaimer

This repository is intended for authorized security research, penetration testing, and educational purposes only. Do not use the techniques described here against systems without explicit authorization.


⚑ MCPJam β†’ Root

CVE-2026-23744 MCPJam Inspector JupyterLab Linux Privilege Escalation

From MCPJam Inspector RCE to root β€” CVE-2026-23744, JupyterLab token disclosure, kernel execution, and OPSMCP privilege escalation.

---

πŸ“– Overview

This repository documents a complete Linux attack chain, from an exposed MCPJam Inspector instance to root-level access.

The chain chains together weaknesses across developer tooling, local services, credential handling, and application authorization:

MCPJam Inspector
       β”‚  CVE-2026-23744
       β–Ό
     RCE
       β”‚
       β–Ό
JupyterLab Token
       β”‚
       β–Ό
Jupyter Kernel
       β”‚
       β–Ό
     User
       β”‚
       β–Ό
  OPSMCP API
       β”‚
       β–Ό
Hidden Admin Tool
       β”‚
       β–Ό
Root Credential
       β”‚
       β–Ό
     root

[!WARNING] This repository is intended for authorized security research, penetration testing, and educational purposes only. Target addresses, credentials, tokens, and other environment-specific values throughout this document are redacted or replaced with lab placeholders.


πŸ“‘ Table of Contents

  • 🎯 Attack Path
  • πŸ”Ž Enumeration
  • πŸ’₯ CVE-2026-23744 β€” MCPJam Inspector RCE
  • πŸ•΅οΈ Internal Enumeration
  • πŸ” JupyterLab Token Disclosure
  • 🧠 JupyterLab Kernel Execution
  • πŸ“‚ OPSMCP Source Code
  • 🚨 Hidden Administrative Function
  • πŸ”‘ Root Credential Disclosure
  • πŸ‘‘ Root
  • πŸ—ΊοΈ Complete Attack Chain
  • 🧩 Vulnerability Summary
  • πŸ›‘οΈ Remediation
  • πŸ” Detection
  • πŸ’‘ Key Takeaways
  • πŸ“š References

🎯 Attack Path

StepStage
1MCPJam Inspector exposed on the network
2CVE-2026-23744 exploited
3Initial RCE achieved
4JupyterLab token disclosed
5Jupyter kernel execution
6User-level shell
7OPSMCP source-code review
8Hardcoded API credential discovered
9Hidden administrative functionality abused
10Root credential disclosed
11root

πŸ”Ž Enumeration

Initial reconnaissance focuses on identifying externally exposed services.

nmap -sC -sV -oN nmap_initial.txt TARGET

A complete TCP scan can then be performed:

nmap -p- --min-rate 5000 -oN nmap_full.txt TARGET

Relevant external services:

PortServiceRole
22SSHRemote administration
6274MCPJam InspectorInitial attack surface

Services bound only to localhost:

PortServicePrivilege
8888JupyterLabUser
5000OPSMCProot

The externally accessible MCPJam Inspector on port 6274 becomes the initial entry point.


πŸ’₯ CVE-2026-23744 β€” MCPJam Inspector RCE

The exposed MCPJam Inspector instance is affected by CVE-2026-23744.

MCPJam Inspector is primarily intended as a development and testing interface for MCP servers. The vulnerability becomes particularly dangerous when this interface is exposed to an untrusted network β€” a vulnerable configuration flow allows attacker-controlled data to reach a command-execution path.

Remote Request
      β”‚
      β–Ό
MCP Server Configuration
      β”‚
      β–Ό
Command Execution
      β”‚
      β–Ό
Initial Shell

The vulnerability affects MCPJam Inspector versions up to and including 1.4.2. For authorized testing, a public proof of concept can be used to validate the vulnerability against the target environment.

After successful exploitation, confirm the execution context:

id
whoami
hostname

πŸ•΅οΈ Internal Enumeration

Once the initial foothold is obtained, local services become visible.

ss -tlnp
ps aux | grep -E 'jupyter|python|node'
                    Network
                       β”‚
                       β–Ό
              MCPJam Inspector
                   :6274
                       β”‚
                       β–Ό
                 Initial RCE
                       β”‚
             β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
             β–Ό                   β–Ό
        JupyterLab             OPSMCP
        :8888/local            :5000/local
             β”‚                   β”‚
             β–Ό                   β–Ό
            User                root

The privilege difference between the two internal applications is particularly interesting.


πŸ” JupyterLab Token Disclosure

The JupyterLab process was started with its authentication token directly on the command line:

--ServerApp.token=<JUPYTER_TOKEN>

The command line can be inspected via:

ps aux | grep jupyter
# or
cat /proc/<PID>/cmdline

This demonstrates a common secret-management problem:

Secret β†’ Command-line argument β†’ Process metadata β†’ Local credential disclosure

The recovered token provides access to the local Jupyter API.


🧠 JupyterLab Kernel Execution

Jupyter exposes a REST API for managing kernels. After authenticating with the recovered token, a kernel can be created via:

POST /api/kernels

The response contains a kernel UUID. Jupyter kernels communicate through WebSockets:

/api/kernels/<KERNEL_ID>/channels

The Jupyter messaging protocol uses an execute_request message to run Python code:

{
  "header": { "msg_type": "execute_request" },
  "content": { "code": "<AUTHORIZED_LAB_CODE>" }
}

This establishes Python execution under the identity of the Jupyter service β€” in this environment, the kernel executes as User.

MCPJam RCE β†’ JupyterLab β†’ User

πŸ“‚ OPSMCP Source Code

With a user shell available, the next step is examining locally installed applications. The OPSMCP application is located under:

/opt/opsmcp/

Reviewing the source code reveals an embedded API credential:

VALID_API_KEY = "<REDACTED_OPSMCP_API_KEY>"

The application also maintains two tool collections:

Visible tools

  • ops.system_status
  • ops.list_services
  • ops.check_disk
  • ops.view_logs

Hidden tools

  • ops._admin_dump
  • ops._debug_mode

The administrative functions are particularly interesting because they are not returned through normal tool enumeration.

Not documented does not mean not accessible.

The backend still registers the hidden tools and accepts their names through the generic tool-execution mechanism.


🚨 Hidden Administrative Function

The application authenticates requests using an API key:

X-API-Key: <OPSMCP_API_KEY>

Once authenticated, the tool-execution endpoint only checks whether the requested function exists β€” not whether the caller is permitted to run it.

What happens:

API Key β†’ Authenticated β†’ Tool exists? β†’ Execute

What should happen:

API Key β†’ Authenticated β†’ Permission check β†’ Allowed β†’ Execute
                                            β”” Denied  β†’ 403

The hidden administrative function can access sensitive root-owned resources.


Download Tool