PT-2026-36759 · Privsim · Mcp-Test-Runner

Brucejqs

·

Published

2026-05-04

·

Updated

2026-05-04

·

CVE-2026-7730

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions privsim mcp-test-runner version 0.2.0
Description A flaw in the MCP Interface component allows for remote OS command injection. This occurs through the manipulation of the command argument within the child process.spawn() function located in the src/index.ts file.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict access to the child process.spawn() function or the MCP Interface component to minimize the risk of exploitation.

Exploit

Command Injection

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-7730

Affected Products

Mcp-Test-Runner