Command Injection Flaw in BurtTheCoder mcp-maigret Vulnerable to Remote Exploitation
CVE-2026-2130

5.3MEDIUM

Key Information:

Vendor
CVE Published:
8 February 2026

What is CVE-2026-2130?

The mcp-maigret product from BurtTheCoder is susceptible to a command injection vulnerability manifesting in the search_username component found in src/index.ts. An attacker can exploit this weakness by manipulating the Username argument, which enables unauthorized command execution remotely. It is highly recommended to upgrade to version 1.0.13, which includes a patch that addresses this vulnerability, sourced from commit b1ae073c4b3e789ab8de36dc6ca8111ae9399e7a.

Affected Version(s)

mcp-maigret 1.0.0

mcp-maigret 1.0.1

mcp-maigret 1.0.2

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Lexpl0it (VulDB User)
.