CVE-2026-26015
CRITICALUnauthenticated RCE in DocsGPT MCP STDIO Configuration
Title source: cnaDescription
DocsGPT is a GPT-powered chat for documentation. From version 0.15.0 to before version 0.16.0, an attacker accessing both the official DocsGPT website or any local and public deployment, can craft a malicious payload bypassing the "MCP test" behavior to achieve arbitrary remote code execution (RCE). This issue has been patched in version 0.16.0.
Scores
CVSS v4
10.0
EPSS
0.0029
EPSS Percentile
52.5%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
total
Details
CWE
CWE-77
Status
published
Products (1)
arc53/DocsGPT
>= 0.15.0, < 0.16.0
Published
Apr 29, 2026
Tracked Since
Apr 29, 2026