PT-2026-24859 · 0Xkoda · Wiremcp
Yinci Chen
·
Published
2026-03-11
·
Updated
2026-03-12
·
CVE-2026-3959
CVSS v3.1
5.3
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
0xKoda WireMCP versions up to 7f45f8b2b4adeb76be8c6227eefb38533fdd6b1e
Description
A flaw exists in 0xKoda WireMCP that allows for operating system command injection. The issue resides in the
server.tool function within the index.js file of the Tshark CLI Command Handler component. Manipulation of this function can lead to the execution of arbitrary commands on the system. The attack requires local access. The exploit for this issue has been publicly released. The product employs a rolling release system, meaning version information for affected or updated releases is not publicly available. The project maintainers were notified of the issue but have not yet responded.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
OS Command Injection
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wiremcp