PT-2026-30512 · Nor2 Io · Heim-Mcp

Yinci Chen

·

Published

2026-04-05

·

Updated

2026-04-05

·

CVE-2026-5602

CVSS v2.0

4.3

Medium

AV:L/AC:L/Au:S/C:P/I:P/A:P
A vulnerability was determined in Nor2-io heim-mcp up to 0.1.3. Impacted is the function registerTools of the file src/tools.ts of the component new heim application/deploy heim application/deploy heim application to cloud. This manipulation causes os command injection. The attack requires local access. The exploit has been publicly disclosed and may be utilized. Patch name: c321d8af25f77668781e6ccb43a1336f9185df37. It is suggested to install a patch to address this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

Exploit

Fix

OS Command Injection

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-5602

Affected Products

Heim-Mcp