Command Injection Flaw in BurtTheCoder mcp-maigret Vulnerable to Remote Exploitation
CVE-2026-2130
5.3MEDIUM
What is CVE-2026-2130?
The mcp-maigret product from BurtTheCoder is susceptible to a command injection vulnerability manifesting in the search_username component found in src/index.ts. An attacker can exploit this weakness by manipulating the Username argument, which enables unauthorized command execution remotely. It is highly recommended to upgrade to version 1.0.13, which includes a patch that addresses this vulnerability, sourced from commit b1ae073c4b3e789ab8de36dc6ca8111ae9399e7a.
Affected Version(s)
mcp-maigret 1.0.0
mcp-maigret 1.0.1
mcp-maigret 1.0.2
