top of page
perceptive_background_267k.jpg

A vulnerability was found in 54yyyu code-mcp up to 4cfc4643541a110c906d93635b391bf7e357f4a8. The impacted element is the function git_operation of the file src/…

Published:

4 mei 2026 om 22:00:00

Alert date:

5 mei 2026 om 06:01:28

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Supply Chain & Dependencies

A command injection vulnerability was discovered in 54yyyu code-mcp up to commit 4cfc4643541a110c906d93635b391bf7e357f4a8. The vulnerability affects the git_operation function in src/code_mcp/server.py of the MCP Tool component. Attackers can manipulate the operation argument to achieve command injection remotely. The exploit has been publicly disclosed and is available for use. The project uses continuous delivery with rolling releases, making version tracking difficult. Despite early notification through an issue report, the project maintainers have not yet responded to address the vulnerability.

Technical details

Mitigation steps:

Affected products:

54yyyu code-mcp

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page