PT-2026-30512 · Nor2 Io · Heim-Mcp
Yinci Chen
·
Published
2026-04-05
·
Updated
2026-04-05
·
CVE-2026-5602
CVSS v2.0
4.3
Medium
| AV:L/AC:L/Au:S/C:P/I:P/A:P |
A vulnerability was determined in Nor2-io heim-mcp up to 0.1.3. Impacted is the function registerTools of the file src/tools.ts of the component new heim application/deploy heim application/deploy heim application to cloud. This manipulation causes os command injection. The attack requires local access. The exploit has been publicly disclosed and may be utilized. Patch name: c321d8af25f77668781e6ccb43a1336f9185df37. It is suggested to install a patch to address this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Exploit
Fix
OS Command Injection
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Heim-Mcp