PT-2026-36552 · Artmin96 · Yii2-Mcp-Server
Eternity
·
Published
2026-05-02
·
Updated
2026-05-02
·
CVE-2026-7600
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
ArtMin96 yii2-mcp-server version 1.0.2
Description
A flaw in the MCP Interface component, specifically within the
yii command help/yii execute command() function of the src/index.ts file, allows for remote OS command injection. This occurs when a manipulation is executed, potentially leading to complete server compromise.Recommendations
Remove version 1.0.2.
As a temporary workaround, restrict access to the
yii command help/yii execute command() function to minimize the risk of exploitation.Exploit
Fix
OS Command Injection
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Yii2-Mcp-Server