PT-2026-25574 · Bazinga012 · Mcp Code Executor

Yinci Chen

·

Published

2026-03-16

·

Updated

2026-03-16

·

CVE-2026-4199

CVSS v3.1

5.3

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions bazinga012 mcp code executor versions up to 0.3.0
Description A flaw exists in the installDependencies function within the src/index.ts file that could allow for command injection. This issue is exploitable only within a local environment and a public exploit is available. The project maintainers were notified of the issue but have not yet responded.
Recommendations Apply a patch to resolve this issue. As a temporary workaround, consider restricting access to the installDependencies function until a patch is available.

Exploit

Fix

Special Elements Injection

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-4199

Affected Products

Mcp Code Executor