lowCVSS 5.3Vulnerability

CVE-2026-5602

A vulnerability was determined in Nor2-io heim-mcp up to 0.1.3. Impacted is the function registerTools of the file src/tools.ts of the component new_heim_application/deploy_heim_application/deploy_heim_application_to_cloud. This manipulation causes os command injection. The attack requires local access. The exploit has been publicly disclosed and may be utilized. Patch name: c321d8af25f77668781e6ccb43a1336f9185df37. It is suggested to install a patch to address this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

Properties

summary
@nor2/heim-mcp vulnerable to command injection
severity
low
epss_score
0.00812
cvss_score
5.3
ghsa_published
2026-04-06T00:30:24Z
source_url
https://github.com/advisories/GHSA-wx4p-jr66-jfp9
ghsa_updated
2026-04-06T18:01:50Z
ghsa_id
GHSA-wx4p-jr66-jfp9
cve_id
CVE-2026-5602
cvss_vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
is_ghsa_only
false
epss_percentile
0.54275

Related Entities (5)

VULNERABLE_TO (1)

[Software]npm/@nor2/heim-mcp

ENRICHED_BY (1)

[Source]FIRST EPSS

REPORTED_BY (1)

[Source]GitHub Advisory Database

AFFECTS (1)

[Software]npm/@nor2/heim-mcp

HAS_WEAKNESS (1)

[Weakness]Improper Neutralization of Special Elements used in a Command ('Command Injection')

Explore deeper with Ninja Signal's threat intelligence graph