OS Command Injection Vulnerability in privsim mcp-test-runner Product
CVE-2026-7730
Key Information:
- Vendor
Privsim
- Status
- Vendor
- CVE Published:
- 4 May 2026
Badges
What is CVE-2026-7730?
A vulnerability has been detected in the privsim mcp-test-runner version 0.2.0 affecting the child_process.spawn function located in src/index.ts. By manipulating the command argument, an attacker could execute arbitrary OS commands, potentially leading to severe security breaches. This vulnerability is exploitable remotely, and public exploits are available, which raises significant concerns about its potential misuse. Despite notification to the project maintainers, a resolution has not been provided.
Affected Version(s)
mcp-test-runner 0.2.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
