CVE-2026-22793

CRITICAL

5ire < 0.15.3 - Remote Code Execution via ECharts Markdown Plugin

Title source: llm
STIX 2.1

Description

5ire is a cross-platform desktop artificial intelligence assistant and model context protocol client. Prior to version 0.15.3, an unsafe option parsing vulnerability in the ECharts Markdown plugin allows any user able to submit ECharts code blocks to execute arbitrary JavaScript code in the renderer context. This can lead to Remote Code Execution (RCE) in environments where privileged APIs (such as Electron’s electron.mcp) are exposed, resulting in full compromise of the host system. Version 0.15.3 patches the issue.

References (2)

Core 2
Core References

Scores

CVSS v3 9.6
EPSS 0.0061
EPSS Percentile 44.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-94
Status published
Products (1)
5ire/5ire < 0.15.3
Published Jan 21, 2026
Tracked Since Feb 18, 2026