PT-2026-45866 · Unknown · Blender-Mcp
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
ahujasid blender-mcp versions prior to 5b37be25242e73dc4cf1328974d30458b9e5d67e
Description
An injection issue exists in the
Open() function within the src/blender mcp/server.py file. This occurs when the input image url argument is manipulated, allowing for remote exploitation.Recommendations
Deploy the patch 5b37be25242e73dc4cf1328974d30458b9e5d67e.
As a temporary workaround, restrict the use of the
input image url argument in the Open() function.Exploit
Fix
Improper Neutralization
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Blender-Mcp