CVE-2026-19047: NocteDefensor LudusMCP ludus_cli_execute cliWrapper.ts executeCommand command injection
A vulnerability was detected in NocteDefensor LudusMCP up to 1.0.24. This affects the function executeArbitraryCommand/executeCommand of the file src/ludusMCP/cliWrapper.ts of the component luduscliexecute. Performing a manipulation of the argument command/args results in command injection. The attack needs to be approached locally. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19047?
The severity of CVE-2026-19047 is medium with a score of 5.3.
What type of vulnerability is CVE-2026-19047?
CVE-2026-19047 is a command injection vulnerability.
How do I fix CVE-2026-19047?
To fix CVE-2026-19047, update NocteDefensor LudusMCP to the latest version greater than 1.0.24.
What components are affected by CVE-2026-19047?
CVE-2026-19047 affects the ludus_cli_execute component in NocteDefensor LudusMCP.
What actions can be exploited in CVE-2026-19047?
CVE-2026-19047 can be exploited by manipulating the command or args arguments in the executeCommand function.