PT-2026-23889 · Ryuzakishinji · Biome-Mcp-Server

·

CVE-2026-3680

·

Published

2026-03-07

·

Updated

2026-03-08

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions RyuzakiShinji biome-mcp-server versions up to 1.0.0
Description A security flaw exists in RyuzakiShinji biome-mcp-server up to version 1.0.0, related to an unknown functionality within the biome-mcp-server.ts file. A manipulation of this functionality can lead to command injection, and the attack can be initiated remotely. The exploit has been publicly released.
Recommendations Apply patch 335e1727147efeef011f1ff8b05dd751d8a660be.

Exploit

Fix

Command Injection

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-3680

Affected Products

Biome-Mcp-Server