CVE-2026-3484: PhialsBasement nmap-mcp-server Nmap CLI index.ts child_process.exec command injection
A vulnerability was detected in PhialsBasement nmap-mcp-server up to bee6d23547d57ae02460022f7c78ac0893092e38. Affected by this issue is the function childprocess.exec of the file src/index.ts of the component Nmap CLI Command Handler. The manipulation results in command injection. The attack may be performed from remote. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The patch is identified as 30a6b9e1c7fa6146f51e28d6ab83a2568d9a3488. It is best practice to apply a patch to resolve this issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3484?
CVE-2026-3484 is classified as a critical vulnerability due to the potential for command injection.
How do I fix CVE-2026-3484?
To fix CVE-2026-3484, update the nmap-mcp-server package to a version beyond bee6d23547d57ae02460022f7c78ac0893092e38.
What systems are affected by CVE-2026-3484?
CVE-2026-3484 affects versions of the nmap-mcp-server package up to and including bee6d23547d57ae02460022f7c78ac0893092e38.
What is the impact of CVE-2026-3484?
The impact of CVE-2026-3484 includes the possibility for attackers to execute arbitrary commands on the affected system.
Is CVE-2026-3484 exploited in the wild?
As of now, there are no confirmed reports of CVE-2026-3484 being actively exploited in the wild.