PT-2026-32188 · Chatboxai+1 · Chatboxai+1
Yu_Bao
·
Published
2026-04-12
·
Updated
2026-04-13
·
CVE-2026-6130
CVSS v2.0
7.5
High
| AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
chatboxai chatbox versions up to 1.20.0
Description
A flaw exists in the StdioClientTransport function within the src/main/mcp/ipc-stdio-transport.ts file of the Model Context Protocol Server Management System component. Manipulation of the
args/env argument can lead to os command injection. The attack can be launched remotely. The exploit has been published.Recommendations
Update to a version beyond 1.20.0.
Exploit
Fix
Command Injection
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Model Context Protocol Server Management System
Chatboxai