lowCVSS 5.3Vulnerability
CVE-2026-5603
A vulnerability was identified in elgentos magento2-dev-mcp up to 1.0.2. The affected element is the function executeMagerun2Command of the file src/index.ts. Such manipulation leads to os command injection. An attack has to be approached locally. The exploit is publicly available and might be used. The name of the patch is aa1ffcc0aea1b212c69787391783af27df15ae9d. A patch should be applied to remediate this issue.
Properties
- summary
- @elgentos/magento2-dev-mcp vulnerable to command injection
- severity
- low
- epss_score
- 0.00812
- cvss_score
- 5.3
- ghsa_published
- 2026-04-06T00:30:24Z
- source_url
- https://github.com/advisories/GHSA-xqv9-qr76-hfq2
- ghsa_updated
- 2026-04-06T18:02:41Z
- ghsa_id
- GHSA-xqv9-qr76-hfq2
- cve_id
- CVE-2026-5603
- cvss_vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
- is_ghsa_only
- false
- epss_percentile
- 0.54274
Related Entities (5)
VULNERABLE_TO (1)
←[Software]npm/@elgentos/magento2-dev-mcp
ENRICHED_BY (1)
→[Source]FIRST EPSS
REPORTED_BY (1)
→[Source]GitHub Advisory Database
AFFECTS (1)
→[Software]npm/@elgentos/magento2-dev-mcp
HAS_WEAKNESS (1)
→[Weakness]Improper Neutralization of Special Elements used in a Command ('Command Injection')
Explore deeper with Ninja Signal's threat intelligence graph