Skip to content

MCPA-2026-0015

mediumrce-vectorsCVSS 5.3

LudusMCP get_credential_from_user command injection via secret-dialog description (CVE-2026-19045)

LudusMCP (npm: ludus-mcp) up to and including 1.0.24 is vulnerable to command injection: SecretDialog.showSecretDialog in src/utils/secretDialog.ts (component get_credential_from_user) interpolates the attacker-influenced Description argument into a shell command, so a poisoned tool call or manipulated description can execute arbitrary commands on the local host. The maintainer was notified via a public issue but no fixed release exists as of 2026-08-06.

Affected packages

EcosystemPackageAffected versions
npmludus-mcp
>= 0, <= 1.0.24

Identifiers

CVE-2026-19045GHSA-5ccg-4qw3-g338CWE-74CWE-77

References

Timeline

  • Published: 2026-08-06

← All advisories