Command Injection Vulnerability in MCP-Server-Taskwarrior by Awwaiid
CVE-2026-5833
Key Information:
- Vendor
Awwaiid
- Status
- Vendor
- CVE Published:
- 9 April 2026
Badges
What is CVE-2026-5833?
A security vulnerability in Awwaiid's MCP-Server-Taskwarrior up to version 1.0.1 allows local attackers to execute arbitrary commands via manipulated arguments in the setRequestHandler function within index.ts. The issue has been publicly disclosed, and a patch (1ee3d282debfa0a99afeb41d22c4b2fd5a3148f2) is available to address the flaw. Users are strongly encouraged to apply the patch to safeguard their systems.
Affected Version(s)
mcp-server-taskwarrior 1.0.0
mcp-server-taskwarrior 1.0.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
