PT-2026-45866 · Unknown · Blender-Mcp

·

CVE-2026-10661

·

Published

2026-06-02

·

Updated

2026-06-04

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions ahujasid blender-mcp versions prior to 5b37be25242e73dc4cf1328974d30458b9e5d67e
Description An injection issue exists in the Open() function within the src/blender mcp/server.py file. This occurs when the input image url argument is manipulated, allowing for remote exploitation.
Recommendations Deploy the patch 5b37be25242e73dc4cf1328974d30458b9e5d67e. As a temporary workaround, restrict the use of the input image url argument in the Open() function.

Exploit

Fix

Improper Neutralization

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-10661

Affected Products

Blender-Mcp