Command Injection Vulnerability in r-huijts xcode-mcp-server
CVE-2026-2178
Key Information:
- Vendor
R-huijts
- Status
- Vendor
- CVE Published:
- 8 February 2026
Badges
What is CVE-2026-2178?
A command injection vulnerability exists in the registerXcodeTools function of the r-huijts xcode-mcp-server, which affects versions prior to f3419f00117aa9949e326f78cc940166c88f18cb. When manipulating the 'args' argument, an attacker can exploit this vulnerability to execute arbitrary commands remotely. The exploit has been made public, raising concerns for users. A patch is available in commit 11f8d6bacadd153beee649f92a78a9dad761f56f, and it is strongly advised that users apply this update promptly to mitigate potential risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
xcode-mcp-server f3419f00117aa9949e326f78cc940166c88f18cb
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
