CVE-2026-26029

HIGH

sf-mcp-server - Command Injection

Title source: llm
STIX 2.1

Description

sf-mcp-server is an implementation of Salesforce MCP server for Claude for Desktop. A command injection vulnerability exists in sf-mcp-server due to unsafe use of child_process.exec when constructing Salesforce CLI commands with user-controlled input. Successful exploitation allows attackers to execute arbitrary shell commands with the privileges of the MCP server process.

Scores

CVSS v3 7.5
EPSS 0.0003
EPSS Percentile 7.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-78
Status published
Products (1)
akutishevsky/sf-mcp-server < 1.0.3
Published Feb 11, 2026
Tracked Since Feb 18, 2026