PT-2026-30513 · Elgentos · Magento 2+1

Yinci Chen

·

Published

2026-04-05

·

Updated

2026-04-21

·

CVE-2026-5603

CVSS v3.1

5.3

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions elgentos magento2-dev-mcp versions up to 1.0.2
Description A flaw exists in elgentos magento2-dev-mcp up to version 1.0.2 due to a command injection issue within the executeMagerun2Command function located in the src/index.ts file. This manipulation can be exploited locally.
Recommendations Apply the patch aa1ffcc0aea1b212c69787391783af27df15ae9d to resolve the issue.

Exploit

Fix

Command Injection

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-5603
GHSA-XQV9-QR76-HFQ2

Affected Products

Magento 2
Magento2-Dev-Mcp