CVE-2026-102911 | zosmaai pi-llm-wiki up to 0.11.7 wiki_capture_source MCP tool mcp/index.ts url os command injection (Issue 185)

SecurityVulns

A vulnerability classified as very critical was found in zosmaai pi-llm-wiki up to 0.11.7. Affected is an unknown function of the file mcp/index.ts of the component wiki_capture_source MCP tool. Executing a manipulation of the argument url can lead to os command injection.

This vulnerability is handled as CVE-2026-102911. The attack can be executed remotely. Additionally, an exploit exists.

Upgrading the affected component is advised.VulDB Recent EntriesRead More