PT-2026-36936 · Unknown · Wireshark-Mcp

Cpt_Penner

·

Published

2026-05-04

·

Updated

2026-05-05

·

CVE-2026-7785

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions wireshark-mcp (affected versions not specified)
Description A security flaw allows remote OS command injection via the quick capture() function within the pyshark mcp.py file. This issue enables an attacker to execute arbitrary commands remotely without requiring privileges or user interaction.
Recommendations As a temporary workaround, consider restricting the use of the quick capture() function until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-7785

Affected Products

Wireshark-Mcp