PT-2026-31572 · Unknown · Awwaiid Mcp-Server-Taskwarrior
CVSS v3.1
5.3
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
awwaiid mcp-server-taskwarrior versions prior to 1.0.2
Description
A command injection issue exists that requires local access to exploit. The problem occurs within the
server.setRequestHandler() function located in the index.ts file, where improper handling of the Identifier argument allows for the execution of arbitrary commands.Recommendations
Update to the version released after patch 1ee3d282debfa0a99afeb41d22c4b2fd5a3148f2.
Exploit
Fix
Command Injection
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Awwaiid Mcp-Server-Taskwarrior