PT-2026-6671 · Isaacwasserman · Mcp-Vegalite-Server
Lexpl0It
·
Published
2026-02-06
·
Updated
2026-02-06
·
CVE-2026-1977
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
isaacwasserman mcp-vegalite-server versions prior to 16aefed598b8cd897b78e99b907f6e2984572c61
Description
A security issue exists in the
eval function of the visualize data component. Manipulation of the vegalite specification argument can lead to code injection. This attack can be initiated remotely. The exploit for this issue has been publicly disclosed.Recommendations
Versions prior to 16aefed598b8cd897b78e99b907f6e2984572c61 should be updated. As a temporary workaround, consider restricting or disabling the use of the
visualize data component until a suitable update is available. Avoid using the vegalite specification parameter in the affected function eval() until the issue is resolved.Exploit
Fix
Special Elements Injection
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mcp-Vegalite-Server