OS Command Injection Vulnerability in RepoMix Command Handler by DeDeveloper23
CVE-2026-5023
Key Information:
- Vendor
Dedeveloper23
- Status
- Vendor
- CVE Published:
- 29 March 2026
Badges
What is CVE-2026-5023?
A security flaw exists within the RepoMix Command Handler in DeDeveloper23's codebase-mcp that allows attackers to inject operating system commands. This vulnerability is located in the getCodebase/getRemoteCodebase/saveCodebase function of the codebase.ts file. It requires local access to exploit but poses significant risks if utilized. The issue was publicly disclosed, and despite a prior report to the project maintainers, no remedial action has yet been taken. Due to the rolling release model, the specific versions affected may vary, complicating mitigation efforts.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
codebase-mcp 3ec749d237dd8eabbeef48657cf917275792fde6
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
