lowCVSS 5.3Vulnerability

CVE-2026-5603

A vulnerability was identified in elgentos magento2-dev-mcp up to 1.0.2. The affected element is the function executeMagerun2Command of the file src/index.ts. Such manipulation leads to os command injection. An attack has to be approached locally. The exploit is publicly available and might be used. The name of the patch is aa1ffcc0aea1b212c69787391783af27df15ae9d. A patch should be applied to remediate this issue.

Properties

summary
@elgentos/magento2-dev-mcp vulnerable to command injection
severity
low
epss_score
0.00812
cvss_score
5.3
ghsa_published
2026-04-06T00:30:24Z
source_url
https://github.com/advisories/GHSA-xqv9-qr76-hfq2
ghsa_updated
2026-04-06T18:02:41Z
ghsa_id
GHSA-xqv9-qr76-hfq2
cve_id
CVE-2026-5603
cvss_vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
is_ghsa_only
false
epss_percentile
0.54274

Related Entities (5)

VULNERABLE_TO (1)

[Software]npm/@elgentos/magento2-dev-mcp

ENRICHED_BY (1)

[Source]FIRST EPSS

REPORTED_BY (1)

[Source]GitHub Advisory Database

AFFECTS (1)

[Software]npm/@elgentos/magento2-dev-mcp

HAS_WEAKNESS (1)

[Weakness]Improper Neutralization of Special Elements used in a Command ('Command Injection')

Explore deeper with Ninja Signal's threat intelligence graph