PT-2026-29087 · Unknown · Raine Consult-Llm-Mcp

Yinci Chen

·

Publicado

2026-03-30

·

Atualizado

2026-03-31

·

CVE-2026-5125

CVSS v3.1

5.3

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions raine consult-llm-mcp versions through 2.5.3
Description A flaw exists in the child process.execSync function within the src/server.ts file. Manipulation of the git diff.base ref/git diff.files argument can lead to operating system command injection. This issue is only exploitable with local access. The exploit is publicly available.
Recommendations Upgrade to version 2.5.4 to address this issue.

Exploit

Correção

Command Injection

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-5125

Produtos afetados

Raine Consult-Llm-Mcp