MCPA-2026-0016
mediumrce-vectorsCVSS 5.3
LudusMCP ludus_cli_execute command injection via command/args arguments (CVE-2026-19047)
LudusMCP (npm: ludus-mcp) up to and including 1.0.24 is vulnerable to command injection: executeArbitraryCommand/executeCommand in src/ludusMCP/cliWrapper.ts (component ludus_cli_execute) passes the attacker-influenced command/args arguments into a shell, so a poisoned tool call can execute arbitrary commands on the local host. The maintainer was notified via a public issue but no fixed release exists as of 2026-08-06.
Affected packages
| Ecosystem | Package | Affected versions |
|---|---|---|
| npm | ludus-mcp | >= 0, <= 1.0.24 |
Identifiers
CVE-2026-19047GHSA-grhp-mc55-jxg8CWE-74CWE-77
References
- advisory https://github.com/advisories/GHSA-grhp-mc55-jxg8
- web https://nvd.nist.gov/vuln/detail/CVE-2026-19047
- report https://github.com/NocteDefensor/LudusMCP/issues/3
Timeline
- Published: 2026-08-06