MEDIUM
ArtMin96 yii2-mcp-server MCP index.ts yii_execute_command os command injection
Published May 2, 2026
5.3
MEDIUMCVSS 4.0
EPSS 1.82%
Description
A flaw has been found in ArtMin96 yii2-mcp-server 1.0.2. This impacts the function yii_command_help/yii_execute_command of the file src/index.ts of the component MCP Interface. Executing a manipulation can lead to os command injection. The attack can be executed remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Affected products
-
- Version 1.0.2StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| ArtMin96 | Yii2-Mcp-Server | n/a |
|
No data.
No data.
No Red Hat product state for this CVE.
yii2-mcp-server
npm
Introduced 0 Fixed not fixed
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | yii2-mcp-server | 0 | not fixed |
Remediation
No remediation recorded yet.
Weaknesses (2)
References (9)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-26725 Advisory
- https://github.com/ArtMin96/yii2-mcp-server product
- https://github.com/ArtMin96/yii2-mcp-server/issues/3 issue-tracking
- https://github.com/BruceJqs/public_exp/issues/29 exploitissue-tracking
- https://github.com/advisories/GHSA-gc8w-x73w-p4rh Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-7600
- https://vuldb.com/submit/805613 third-party-advisory
- https://vuldb.com/vuln/360557 vdb-entrytechnical-description
- https://vuldb.com/vuln/360557/cti signaturepermissions-required
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-26725 | Advisory | |
| https://github.com/ArtMin96/yii2-mcp-server | product | |
| https://github.com/ArtMin96/yii2-mcp-server/issues/3 | issue-tracking | |
| https://github.com/BruceJqs/public_exp/issues/29 | exploitissue-tracking | |
| https://github.com/advisories/GHSA-gc8w-x73w-p4rh | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-7600 | ||
| https://vuldb.com/submit/805613 | third-party-advisory | |
| https://vuldb.com/vuln/360557 | vdb-entrytechnical-description | |
| https://vuldb.com/vuln/360557/cti | signaturepermissions-required |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published May 2, 2026
Updated May 4, 2026
Reserved May 1, 2026
Link CVE-2026-7600
CISA Vulnrichment
Updated May 4, 2026
ENISA EUVD
EUVD-2026-26725 GHSA-GC8W-X73W-P4RH Assigner VulDB
Published May 2, 2026
Updated May 4, 2026
Exploited since n/a
Link EUVD-2026-26725