Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Spdc-Elm

#31747of 53,625
8.1Total CVSS
Vulnerabilities · 1
PT-2026-39708
8.1
2026-05-11
Unknown · Automagik-Genie · CVE-2026-30635
**Name of the Vulnerable Software and Affected Versions** automagik-genie version 2.5.27 **Description** Command injection allows attackers to execute arbitrary commands through the 'view task' (also known as 'view') within the `readTranscriptFromCommit()` function located in 'dist/mcp/server.js'. This occurs when a user reads from an external `FORGE BASE URL`. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.