PT-2026-24859 · 0Xkoda · Wiremcp

Yinci Chen

·

Publicado

2026-03-11

·

Atualizado

2026-03-12

·

CVE-2026-3959

CVSS v3.1

5.3

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions 0xKoda WireMCP versions up to 7f45f8b2b4adeb76be8c6227eefb38533fdd6b1e
Description A flaw exists in 0xKoda WireMCP that allows for operating system command injection. The issue resides in the server.tool function within the index.js file of the Tshark CLI Command Handler component. Manipulation of this function can lead to the execution of arbitrary commands on the system. The attack requires local access. The exploit for this issue has been publicly released. The product employs a rolling release system, meaning version information for affected or updated releases is not publicly available. The project maintainers were notified of the issue but have not yet responded.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-3959

Produtos afetados

Wiremcp