PT-2026-45876 · Unknown · Blender-Mcp
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
ahujasid blender-mcp versions prior to 7636d13bded82eca58eb93c3f4cd8708dfdfbe8b
Description
Remote code injection is possible through the manipulation of the
code argument within the execute blender code() function located in the /src/blender mcp/server.py file.Recommendations
Update to a version later than 7636d13bded82eca58eb93c3f4cd8708dfdfbe8b.
As a temporary workaround, restrict access to the
execute blender code() function to minimize the risk of exploitation.Exploit
Fix
Code Injection
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Blender-Mcp