PT-2026-30562 · Braffolk · Mcp-Summarization-Functions
Brucejin
·
Published
2026-04-06
·
Updated
2026-04-06
·
CVE-2026-5619
CVSS v3.1
5.3
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Braffolk mcp-summarization-functions versions up to 0.1.5
Description
A flaw exists in Braffolk mcp-summarization-functions up to version 0.1.5. The issue impacts an unknown function within the
src/server/mcp-server.ts file of the summarize command component. Manipulation of the command argument can lead to operating system command injection. Local access is required for exploitation. The exploit has been published.Recommendations
Update to a version beyond 0.1.5.
Exploit
Fix
Command Injection
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mcp-Summarization-Functions