CVE-2026-7785

HIGH

A-G-U-P-T-A wireshark-mcp pyshark_mcp.py quick_capture os command injection

Title source: cna
STIX 2.1

Description

A security flaw has been discovered in A-G-U-P-T-A wireshark-mcp edaf604416fbc94a201b4043092d4a1b09a12275/400c3da70074f22f3cce7ccb65304cafc7089c89. This affects the function quick_capture of the file pyshark_mcp.py. The manipulation results in os command injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. The project was informed of the problem early through an issue report but has not responded yet.

References (5)

Core 5
Core References
Vdb Entry, Technical Description vdb-entry technical-description
VDB-360985 | A-G-U-P-T-A wireshark-mcp pyshark_mcp.py quick_capture os command injection
https://vuldb.com/vuln/360985
Signature, Permissions Required signature permissions-required
VDB-360985 | CTI Indicators (IOB, IOC, TTP, IOA)
https://vuldb.com/vuln/360985/cti
Third Party Advisory third-party-advisory
Submit #807745 | A-G-U-P-T-A wireshark-mcp 400c3da70074f22f3cce7ccb65304cafc7089c89 Command Injection
https://vuldb.com/submit/807745

Scores

CVSS v3 7.3
EPSS 0.0131
EPSS Percentile 66.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-77 CWE-78
Status published
Products (2)
A-G-U-P-T-A/wireshark-mcp 400c3da70074f22f3cce7ccb65304cafc7089c89
A-G-U-P-T-A/wireshark-mcp edaf604416fbc94a201b4043092d4a1b09a12275
Published May 05, 2026
Tracked Since May 05, 2026