CVE-2026-78430 | sworddut mcp-ffmpeg-helper 0.1.0/0.1.1/0.2.1 Tool src/tools/handlers.ts handleToolCall format os command injection
A vulnerability categorized as problematic has been discovered in sworddut mcp-ffmpeg-helper 0.1.0/0.1.1/0.2.1. This affects the function handleToolCall of the file src/tools/handlers.ts of the component Tool Handler. The manipulation of the argument format results in os command injection.
This vulnerability is known as CVE-2026-78430. Attacking locally is a requirement. Furthermore, an exploit is available.
The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More