Command Injection Vulnerability in mcp-server-siri-shortcuts by Vendor
CVE-2026-0758
What is CVE-2026-0758?
The mcp-server-siri-shortcuts contains a critical command injection vulnerability due to improper validation of the shortcutName parameter. This flaw allows local attackers who already have low-privileged access to escalate their privileges by executing arbitrary code within the context of the service account. Successful exploitation necessitates that the attacker carefully craft inputs that originate from user input, which are then processed without sufficient checks. This vulnerability poses a significant risk to the integrity and security of the system, making it essential for users to promptly address the issue.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
mcp-server-siri-shortcuts 49d67127ba8373300d0c9d94c059b4c873bf2ef8
References
CVSS V3.0
Timeline
Vulnerability published
Vulnerability Reserved
