Command Injection Vulnerability in kylecui NetForensicMCP Product
CVE-2026-75011
Key Information:
- Vendor
Kylecui
- Status
- Vendor
- CVE Published:
- 17 August 2026
Badges
What is CVE-2026-75011?
A command injection vulnerability exists in the kylecui NetForensicMCP version 2.1.0, specifically within the execAsync function located in index.js. By manipulating the argument for the interface/protocol, an attacker can execute arbitrary commands remotely. This significant security flaw has been publicly acknowledged, and despite prior notifications regarding the issue, there has been no response from the developers. As such, the potential for exploitation remains high, posing risks to the integrity of systems utilizing this product.
Affected Version(s)
NetForensicMCP 2.1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
