


Perceptive Security
SOC/SIEM Consultancy

A security flaw has been discovered in egtai gmx-vmd-mcp up to 0.1.0. This issue affects the function launch_vmd_gui_tool of the file mcp_server.py of the compo…
Published:
27 april 2026 om 22:00:00
Alert date:
28 april 2026 om 04:01:34
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications
A critical command injection vulnerability (CVE-2026-7215) has been discovered in egtai gmx-vmd-mcp up to version 0.1.0. The vulnerability affects the launch_vmd_gui_tool function in mcp_server.py of the VMD Launch Handler component. Attackers can exploit this flaw by manipulating the structure_file/trajectory_file arguments to achieve command injection. The vulnerability can be exploited remotely and a public exploit is available. The project maintainers have been notified through an issue report but have not yet responded to the vulnerability disclosure.
Technical details
Mitigation steps:
Affected products:
egtai gmx-vmd-mcp
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-7215
https://github.com/egtai/gmx-vmd-mcp/
https://github.com/egtai/gmx-vmd-mcp/issues/2
https://vuldb.com/submit/802087
https://vuldb.com/vuln/359815
https://vuldb.com/vuln/359815/cti
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
