9.7
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Description
5ire is a cross-platform desktop artificial intelligence assistant and model context protocol client. Prior to version 0.15.3, an unsafe option parsing vulnerability in the ECharts Markdown plugin allows any user able to submit ECharts code blocks to execute arbitrary JavaScript code in the renderer context. This can lead to Remote Code Execution (RCE) in environments where privileged APIs (such as Electronβs electron.mcp) are exposed, resulting in full compromise of the host system. Version 0.15.3 patches the issue.
Basic Information
ID
CVE-2026-22793
Source
GitHub_M
Published
Jan 21, 2026 at 21:06
Modified
Jan 21, 2026 at 21:26
Affected Product
Vendor
nanbingxyz
Product
5ire
Version
< 0.15.3
Affected Versions
nanbingxyz 5ire < 0.15.3