OS Command Injection Vulnerability in elgentos Magento2-Dev-MCP
CVE-2026-5603
Key Information:
- Vendor
Elgentos
- Status
- Vendor
- CVE Published:
- 5 April 2026
Badges
What is CVE-2026-5603?
A critical vulnerability has been discovered in the elgentos Magento2-Dev-MCP up to version 1.0.2, specifically in the executeMagerun2Command function located in src/index.ts. This vulnerability allows for OS command injection, potentially enabling attackers to execute arbitrary commands on the system. An exploit must be executed locally, and there is a publicly available exploit that poses a risk to users. It is essential to apply the provided patch (aa1ffcc0aea1b212c69787391783af27df15ae9d) to remedy this security flaw and protect your systems from potential breaches.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
magento2-dev-mcp 1.0.0
magento2-dev-mcp 1.0.1
magento2-dev-mcp 1.0.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
