CVE-2026-19047 | NocteDefensor LudusMCP up to 1.0.24 ludus_cli_execute cliWrapper.ts executeArbitraryCommand/executeCommand command/args command injection

SecurityVulns

A vulnerability identified as critical has been detected in NocteDefensor LudusMCP up to 1.0.24. This affects the function executeArbitraryCommand/executeCommand of the file src/ludusMCP/cliWrapper.ts of the component ludus_cli_execute. Performing a manipulation of the argument command/args results in command injection.

This vulnerability was named CVE-2026-19047. The attack needs to be approached locally. In addition, an exploit is available.

The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More