Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xqv9-qr76-hfq2

Опубликовано: 06 апр. 2026
Источник: github
Github: Прошло ревью
CVSS4: 1.9
CVSS3: 5.3

Описание

@elgentos/magento2-dev-mcp vulnerable to command injection

A vulnerability was identified in elgentos magento2-dev-mcp up to 1.0.2. The affected element is the function executeMagerun2Command of the file src/index.ts. Such manipulation leads to os command injection. An attack has to be approached locally. The exploit is publicly available and might be used. The name of the patch is aa1ffcc0aea1b212c69787391783af27df15ae9d. A patch should be applied to remediate this issue.

Пакеты

Наименование

@elgentos/magento2-dev-mcp

npm
Затронутые версииВерсия исправления

<= 1.0.2

Отсутствует

EPSS

Процентиль: 18%
0.00058
Низкий

1.9 Low

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-77

Связанные уязвимости

CVSS3: 5.3
nvd
2 дня назад

A vulnerability was identified in elgentos magento2-dev-mcp up to 1.0.2. The affected element is the function executeMagerun2Command of the file src/index.ts. Such manipulation leads to os command injection. An attack has to be approached locally. The exploit is publicly available and might be used. The name of the patch is aa1ffcc0aea1b212c69787391783af27df15ae9d. A patch should be applied to remediate this issue.

EPSS

Процентиль: 18%
0.00058
Низкий

1.9 Low

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-77