OS Command Injection Vulnerability in RepoMix Command Handler by DeDeveloper23
CVE-2026-5023

4.8MEDIUM

Key Information:

Vendor
CVE Published:
29 March 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-5023?

A security flaw exists within the RepoMix Command Handler in DeDeveloper23's codebase-mcp that allows attackers to inject operating system commands. This vulnerability is located in the getCodebase/getRemoteCodebase/saveCodebase function of the codebase.ts file. It requires local access to exploit but poses significant risks if utilized. The issue was publicly disclosed, and despite a prior report to the project maintainers, no remedial action has yet been taken. Due to the rolling release model, the specific versions affected may vary, complicating mitigation efforts.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

codebase-mcp 3ec749d237dd8eabbeef48657cf917275792fde6

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yinci Chen (VulDB User)
.