CVE-2026-6130

HIGH

chatboxai chatbox Model Context Protocol Server Management System ipc-stdio-transport.ts StdioClientTransport os command injection

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-6130. PoCs published by fan-67.

AI-analyzed exploit summary This repository contains a functional MCP (Model Context Protocol) server with file system operations, command execution, and HTTP/stdio transport. It includes tools for file manipulation, command execution, and progressive tool discovery, making it a potential exploit for local file system access and command execution.

Description

A flaw has been found in chatboxai chatbox up to 1.20.0. This impacts the function StdioClientTransport of the file src/main/mcp/ipc-stdio-transport.ts of the component Model Context Protocol Server Management System. Executing a manipulation of the argument args/env can lead to os command injection. The attack can be launched remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Exploits (1)

nomisec WORKING POC
by fan-67 · poc
https://github.com/fan-67/local-mcp

This repository contains a functional MCP (Model Context Protocol) server with file system operations, command execution, and HTTP/stdio transport. It includes tools for file manipulation, command execution, and progressive tool discovery, making it a potential exploit for local file system access and command execution.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: local-mcp (Model Context Protocol server)
No auth needed
Prerequisites: Node.js >= 22.0.0 · Access to the target system
devstral-2 · analyzed Jun 13, 2026 Full analysis →

References (6)

Core 6
Core References
Vdb Entry, Technical Description vdb-entry technical-description
VDB-356993 | chatboxai chatbox Model Context Protocol Server Management System ipc-stdio-transport.ts StdioClientTransport os command injection
https://vuldb.com/vuln/356993
Signature, Permissions Required signature permissions-required
VDB-356993 | CTI Indicators (IOB, IOC, TTP, IOA)
https://vuldb.com/vuln/356993/cti
Third Party Advisory third-party-advisory
Submit #795355 | chatboxai chatbox 1.20.0 Arbitrary Command Execution
https://vuldb.com/submit/795355
Issue Tracking issue-tracking
https://github.com/chatboxai/chatbox/issues/3627

Scores

CVSS v3 7.3
EPSS 0.0137
EPSS Percentile 68.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-77 CWE-78
Status published
Products (21)
chatboxai/chatbox 1.0
chatboxai/chatbox 1.1
chatboxai/chatbox 1.10
chatboxai/chatbox 1.11
chatboxai/chatbox 1.12
chatboxai/chatbox 1.13
chatboxai/chatbox 1.14
chatboxai/chatbox 1.15
chatboxai/chatbox 1.16
chatboxai/chatbox 1.17
... and 11 more
Published Apr 12, 2026
Tracked Since Apr 13, 2026