CVE-2026-4199
MEDIUMbazinga012 mcp_code_executor index.ts installDependencies command injection
Title source: cnaDescription
A vulnerability was identified in bazinga012 mcp_code_executor up to 0.3.0. Affected by this issue is the function installDependencies of the file src/index.ts. Such manipulation leads to command injection. The attack can only be performed from a local environment. The exploit is publicly available and might be used. It is best practice to apply a patch to resolve this issue. The project was informed of the problem early through an issue report but has not responded yet.
References (7)
Core 7
Core References
Vdb Entry, Technical Description vdb-entry
technical-description
VDB-351111 | bazinga012 mcp_code_executor index.ts installDependencies command injection
https://vuldb.com/?id.351111
Signature, Permissions Required signature
permissions-required
VDB-351111 | CTI Indicators (IOB, IOC, TTP, IOA)
https://vuldb.com/?ctiid.351111
Third Party Advisory third-party-advisory
Submit #770424 | bazinga012 mcp_code_executor <=0.3.0 Command Injection
https://vuldb.com/?submit.770424
Issue Tracking issue-tracking
https://github.com/bazinga012/mcp_code_executor/issues/17
Exploit exploit
https://github.com/user-attachments/files/25931133/mcp_code_executor_security_advisory.pdf
Patch issue-tracking
patch
https://github.com/bazinga012/mcp_code_executor/pull/18/commits/a94ec2fea318597646ba1c44d8e44eb1c9196d20
Product product
https://github.com/bazinga012/mcp_code_executor/
Scores
CVSS v3
5.3
EPSS
0.0064
EPSS Percentile
45.6%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-74
CWE-77
Status
published
Products (3)
bazinga012/mcp_code_executor
0.1
bazinga012/mcp_code_executor
0.2
bazinga012/mcp_code_executor
0.3.0
Published
Mar 16, 2026
Tracked Since
Mar 16, 2026