CVE-2026-75011: kylecui NetForensicMCP index.js execAsync command injection
A flaw has been found in kylecui NetForensicMCP 2.1.0. Impacted is the function execAsync of the file index.js. Executing a manipulation of the argument interface/protocol can lead to command injection. The attack may be launched remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-75011?
The severity of CVE-2026-75011 is medium with a score of 6.3.
How do I fix CVE-2026-75011?
To fix CVE-2026-75011, consider updating to the latest version of kylecui NetForensicMCP or applying patches that mitigate command injection vulnerabilities.
What type of vulnerability is CVE-2026-75011?
CVE-2026-75011 is classified as a command injection vulnerability.
Can CVE-2026-75011 be exploited remotely?
Yes, CVE-2026-75011 can be exploited remotely by manipulating the execAsync function's arguments.
Which component is affected by CVE-2026-75011?
CVE-2026-75011 affects the execAsync function in the index.js file of kylecui NetForensicMCP version 2.1.0.