mediumCVSS 7.3Vulnerability

CVE-2026-7446

A vulnerability was detected in VetCoders mcp-server-semgrep 1.0.0. This affects the function analyze_results/filter_results/export_results/compare_results/scan_directory/create_rule of the file src/index.ts of the component MCP Interface. The manipulation of the argument ID results in os command injection. The attack can be executed remotely. The exploit is now public and may be used. Upgrading to version 1.0.1 is able to mitigate this issue. The patch is identified as 141335da044e53c3f5b315e0386e01238405b771. It is advisable to upgrade the affected component.

Properties

severity
medium
summary
mcp-server-semgrep has a Command Injection issue
epss_score
0.01396
cvss_score
7.3
ghsa_published
2026-04-30T00:31:22Z
source_url
https://github.com/advisories/GHSA-86hp-qxqp-w9wv
ghsa_updated
2026-05-06T23:28:37Z
ghsa_id
GHSA-86hp-qxqp-w9wv
cve_id
CVE-2026-7446
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
signal_observed_at
2026-09-11T17:55:57+00:00
is_ghsa_only
false
epss_percentile
0.71165

Related Entities (5)

ENRICHED_BY (1)

[Source]FIRST EPSS

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]npm/mcp-server-semgrep

AFFECTS (1)

[Software]npm/mcp-server-semgrep

HAS_WEAKNESS (1)

[Weakness]Improper Neutralization of Special Elements used in a Command ('Command Injection')

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-7446 (CVSS 7.3) — Ninja Signal Threat Intelligence | Ninja Signal