PT-2026-33073 · Upsonic · Upsonic
Published
2026-04-15
·
Updated
2026-04-29
·
CVE-2026-30625
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Upsonic version 0.71.6
Description
An issue exists in the MCP server/task creation functionality where users can define MCP tasks with arbitrary
command and args values. While an allowlist is implemented, specific permitted commands such as npm and npx accept argument flags that allow the execution of arbitrary OS commands. This can lead to remote code execution with the privileges of the Upsonic process.Recommendations
Update to version 0.72.0.
Restrict network access to mitigate risk.
Fix
RCE
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Upsonic