OS Command Injection Vulnerability in BurtTheCoder MCP-DNSTwist
CVE-2026-7443
Key Information:
- Vendor
Burtthecoder
- Status
- Vendor
- CVE Published:
- 29 April 2026
Badges
What is CVE-2026-7443?
A critical security issue has been discovered in the BurtTheCoder MCP-DNSTwist application, specifically within the fuzz_domain function located in src/index.ts. This vulnerability allows attackers to manipulate request arguments, resulting in potential OS command injection. The issue is concerning as it can be executed remotely, exposing users to significant risks. Attackers may exploit this vulnerability, as details of the exploit have been publicly released. Despite early notification to the project team, no formal response has been issued to address this pressing security concern.
Affected Version(s)
mcp-dnstwist 1.0.0
mcp-dnstwist 1.0.1
mcp-dnstwist 1.0.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
