PT-2026-3863 · 5Ire · 5Ire

C2An1

·

Publicado

2026-01-21

·

Atualizado

2026-01-22

·

CVE-2026-22792

CVSS v3.1

9.6

Crítica

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions 5ire versions prior to 0.15.3
Description 5ire is a cross-platform desktop artificial intelligence assistant and model context protocol client. Prior to version 0.15.3, unsafe HTML rendering allows untrusted HTML, including on* event attributes, to execute within the renderer context. An attacker can inject an <img onerror=...> payload to execute arbitrary JavaScript in the renderer. This JavaScript can call exposed bridge APIs, such as window.bridge.mcpServersManager.createServer, potentially leading to unauthorized creation of MCP servers and remote command execution.
Recommendations Update to version 0.15.3 or later.

Exploit

Correção

RCE

Improper Encoding or Escaping of Output

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-22792
GHSA-P5FM-WM8G-RFFX

Produtos afetados

5Ire