CVE-2026-26015

CRITICAL

Unauthenticated RCE in DocsGPT MCP STDIO Configuration

Title source: cna
STIX 2.1

Description

DocsGPT is a GPT-powered chat for documentation. From version 0.15.0 to before version 0.16.0, an attacker accessing both the official DocsGPT website or any local and public deployment, can craft a malicious payload bypassing the "MCP test" behavior to achieve arbitrary remote code execution (RCE). This issue has been patched in version 0.16.0.

Scores

CVSS v4 10.0
EPSS 0.0029
EPSS Percentile 52.5%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-77
Status published
Products (1)
arc53/DocsGPT >= 0.15.0, < 0.16.0
Published Apr 29, 2026
Tracked Since Apr 29, 2026