lowCVSS 5.3Vulnerability

CVE-2026-5833

A security vulnerability has been detected in awwaiid mcp-server-taskwarrior up to 1.0.1. This impacts the function server.setRequestHandler of the file index.ts. Such manipulation of the argument Identifier leads to command injection. The attack must be carried out locally. The exploit has been disclosed publicly and may be used. The name of the patch is 1ee3d282debfa0a99afeb41d22c4b2fd5a3148f2. Applying a patch is advised to resolve this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

Properties

summary
awwaiid mcp-server-taskwarrior vulnerable to command injection
severity
low
epss_score
0.00647
cvss_score
5.3
ghsa_published
2026-04-09T06:30:27Z
source_url
https://github.com/advisories/GHSA-95hg-3c55-xf9x
ghsa_updated
2026-04-10T19:20:17Z
ghsa_id
GHSA-95hg-3c55-xf9x
cve_id
CVE-2026-5833
cvss_vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
is_ghsa_only
false
epss_percentile
0.48072

Related Entities (5)

VULNERABLE_TO (1)

[Software]npm/mcp-server-taskwarrior

ENRICHED_BY (1)

[Source]FIRST EPSS

REPORTED_BY (1)

[Source]GitHub Advisory Database

AFFECTS (1)

[Software]npm/mcp-server-taskwarrior

HAS_WEAKNESS (1)

[Weakness]Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-5833 (CVSS 5.3) — Ninja Signal Threat Intelligence | Ninja Signal