PT-2026-3261 · Dive · Dive

Tonycrane

·

Publicado

2026-01-16

·

Atualizado

2026-02-09

·

CVE-2026-23523

CVSS v3.1

9.6

Crítica

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dive versions prior to 0.13.0
Description Dive is an open-source MCP Host Desktop Application that integrates with function-calling LLMs. A crafted deeplink can install an attacker-controlled MCP server configuration without sufficient user confirmation, potentially leading to arbitrary local command execution on the victim’s machine. The vulnerability is related to the handling of deeplinks and the installation of MCP server configurations.
Recommendations Update Dive to version 0.13.0 or later.

Exploit

Correção

RCE

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-23523
GHSA-PJJ5-F3WM-F9M8

Produtos afetados

Dive