Aller au contenu

Fiche vulnérabilité

CVE-2026-78430 : vulnérabilité moyenne (CVSS 5.3)

Description

A vulnerability was detected in sworddut mcp-ffmpeg-helper 0.1.0/0.1.1/0.2.1. This affects the function handleToolCall of the file src/tools/handlers.ts of the component Tool Handler. The manipulation of the argument format results in os command injection. Attacking locally is a requirement. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

En bref

Sévérité
Moyenne (CVSS 5.3)
Vecteur CVSS
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Exploitation active
Non signalée par la CISA
Publication
24 août 2026
Dernière mise à jour
26 août 2026

Références

Rechercher une autre vulnérabilité dans la base CVE