


Perceptive Security
SOC/SIEM Consultancy

A weakness has been identified in Toowiredd chatgpt-mcp-server up to 0.1.0. Affected by this issue is some unknown functionality of the file src/services/docker…
Published:
25 april 2026 om 22:00:00
Alert date:
26 april 2026 om 23:04:07
Source:
nvd.nist.gov
Web Technologies, Supply Chain & Dependencies
CVE-2026-7061 affects Toowiredd chatgpt-mcp-server up to version 0.1.0. The vulnerability is located in the docker.service.ts file of the MCP/HTTP component. It allows for OS command injection through manipulation of unknown functionality. The vulnerability can be exploited remotely and a public exploit is available. The project maintainers have been notified through an issue report but have not yet responded to the security disclosure.
Technical details
Mitigation steps:
Affected products:
Toowiredd chatgpt-mcp-server
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-7061
https://github.com/Toowiredd/chatgpt-mcp-server/
https://github.com/Toowiredd/chatgpt-mcp-server/issues/8
https://github.com/wing3e/public_exp/issues/28
https://vuldb.com/submit/798613
https://vuldb.com/vuln/359636
https://vuldb.com/vuln/359636/cti
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
