PT-2026-39708 · Unknown · Automagik-Genie

Spdc-Elm

·

Published

2026-05-11

·

Updated

2026-05-11

·

CVE-2026-30635

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions automagik-genie version 2.5.27
Description Command injection allows attackers to execute arbitrary commands through the 'view task' (also known as 'view') within the readTranscriptFromCommit() function located in 'dist/mcp/server.js'. This occurs when a user reads from an external FORGE BASE URL.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-30635
GHSA-64VR-4GR2-M642

Affected Products

Automagik-Genie