PT-2026-36552 · Artmin96 · Yii2-Mcp-Server

Eternity

·

Published

2026-05-02

·

Updated

2026-05-02

·

CVE-2026-7600

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ArtMin96 yii2-mcp-server version 1.0.2
Description A flaw in the MCP Interface component, specifically within the yii command help/yii execute command() function of the src/index.ts file, allows for remote OS command injection. This occurs when a manipulation is executed, potentially leading to complete server compromise.
Recommendations Remove version 1.0.2. As a temporary workaround, restrict access to the yii command help/yii execute command() function to minimize the risk of exploitation.

Exploit

Fix

OS Command Injection

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-7600
GHSA-GC8W-X73W-P4RH

Affected Products

Yii2-Mcp-Server