


Perceptive Security
SOC/SIEM Consultancy

A security vulnerability has been detected in Sunwood-ai-labs command-executor-mcp-server up to 0.1.0. This impacts the function execute_command of the file src…
Published:
30 April 2026 at 22:00:00
Alert date:
1 May 2026 at 22:01:21
Source:
nvd.nist.gov
Supply Chain & Dependencies, Web Technologies
A critical OS command injection vulnerability (CVE-2026-7593) has been identified in Sunwood-ai-labs command-executor-mcp-server up to version 0.1.0. The vulnerability affects the execute_command function in src/index.ts of the MCP Interface component. Remote exploitation is possible through manipulation leading to OS command injection. The exploit has been publicly disclosed and may be actively used. The project maintainers were notified through an issue report but have not yet responded to address the vulnerability.
Technical details
Mitigation steps:
Affected products:
Sunwood-ai-labs command-executor-mcp-server
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-7593
https://github.com/Sunwood-ai-labs/command-executor-mcp-server/
https://github.com/Sunwood-ai-labs/command-executor-mcp-server/issues/6
https://vuldb.com/submit/805507
https://vuldb.com/vuln/360546
https://vuldb.com/vuln/360546/cti
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
