PT-2026-45876 · Unknown · Blender-Mcp

·

CVE-2026-10688

·

Published

2026-06-02

·

Updated

2026-06-04

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ahujasid blender-mcp versions prior to 7636d13bded82eca58eb93c3f4cd8708dfdfbe8b
Description Remote code injection is possible through the manipulation of the code argument within the execute blender code() function located in the /src/blender mcp/server.py file.
Recommendations Update to a version later than 7636d13bded82eca58eb93c3f4cd8708dfdfbe8b. As a temporary workaround, restrict access to the execute blender code() function to minimize the risk of exploitation.

Exploit

Fix

Code Injection

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-10688

Affected Products

Blender-Mcp