Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-23523

Опубликовано: 16 янв. 2026
Источник: nvd
CVSS3: 9.6
EPSS Низкий

Описание

Dive is an open-source MCP Host Desktop Application that enables integration with function-calling LLMs. Prior to 0.13.0, crafted deeplink can install an attacker-controlled MCP server configuration without sufficient user confirmation and can lead to arbitrary local command execution on the victim’s machine. This vulnerability is fixed in 0.13.0.

EPSS

Процентиль: 13%
0.00044
Низкий

9.6 Critical

CVSS3

Дефекты

CWE-94

EPSS

Процентиль: 13%
0.00044
Низкий

9.6 Critical

CVSS3

Дефекты

CWE-94