Skip to content

MCPA-2026-0016

mediumrce-vectorsCVSS 5.3

LudusMCP ludus_cli_execute command injection via command/args arguments (CVE-2026-19047)

LudusMCP (npm: ludus-mcp) up to and including 1.0.24 is vulnerable to command injection: executeArbitraryCommand/executeCommand in src/ludusMCP/cliWrapper.ts (component ludus_cli_execute) passes the attacker-influenced command/args arguments into a shell, so a poisoned tool call can execute arbitrary commands on the local host. The maintainer was notified via a public issue but no fixed release exists as of 2026-08-06.

Affected packages

EcosystemPackageAffected versions
npmludus-mcp
>= 0, <= 1.0.24

Identifiers

CVE-2026-19047GHSA-grhp-mc55-jxg8CWE-74CWE-77

References

Timeline

  • Published: 2026-08-06

← All advisories