CVE-2026-81735 | ByteDance UI-TARS-desktop mcp-http-server startServer.ts startSseAndStreamableHttpMcpServer os command injection
A vulnerability was found in ByteDance UI-TARS-desktop. It has been classified as critical. This affects the function startSseAndStreamableHttpMcpServer of the file startServer.ts of the component mcp-http-server. Performing a manipulation results in os command injection.
This vulnerability is identified as CVE-2026-81735. The attack can be initiated remotely. There is not any exploit available.
Applying a patch is the recommended action to fix this issue.VulDB Recent EntriesRead More