Command Injection Vulnerability in NocteDefensor LudusMCP Software
CVE-2026-19045

4.8MEDIUM

Key Information:

Status
Vendor
CVE Published:
6 August 2026

What is CVE-2026-19045?

A command injection vulnerability exists in the NocteDefensor LudusMCP software, notably in the function SecretDialog.showSecretDialog found in src/utils/secretDialog.ts. This issue arises from improper handling of the argument Description within the component get_credential_from_user, allowing an attacker to execute arbitrary commands on the local host. Despite early reporting of this flaw, the project's team has yet to provide a response or mitigation. Users should be aware of the potential risks associated with this vulnerability and take necessary precautions.

Affected Version(s)

LudusMCP 1.0.0

LudusMCP 1.0.1

LudusMCP 1.0.2

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

gongyanyu (VulDB User)
VulDB CNA Team
.