CVE 9.8 CRITICAL

CVE-2026-30625_CVE-2026-30625

9.8 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

Upsonic 0.71.6 contains a remote code execution vulnerability in its MCP server/task creation functionality. The application allows users to define MCP tasks with arbitrary command and args values. Although an allowlist exists, certain allowed commands (npm, npx) accept argument flags that enable execution of arbitrary OS commands. Maliciously crafted MCP tasks may lead to remote code execution with the privileges of the Upsonic process. In version 0.72.0 Upsonic added a warning about using Stdio servers being able to execute commands directly on the machine.

AI Analysis

Remote code execution vulnerability in Upsonic's MCP server/task creation functionality

Basic Information

ID CVE-2026-30625
Source mitre
Published Apr 15, 2026 at 00:00
Modified Apr 16, 2026 at 13:55

Affected Product

Vendor Upsonic
Product Upsonic
Version 0.71.6
Affected Versions n/a n/a n/a

CWE Classification

AI Assessment

AI Score 9.8 / 10
AI Severity Critical
Vendor Upsonic
Product Upsonic
Version 0.71.6

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.