CVE-2026-105797

Source
https://cve.org/CVERecord?id=CVE-2026-105797
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-105797.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-105797
Aliases
  • GHSA-h4mw-qw8m-5x4j
Published
2026-10-06T14:23:42Z
Modified
2026-10-08T02:50:43Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
SimpleChat: Command injection via authorization-gate ordering flaw (arbitrary process spawn through MCP stdio transport)
Details

SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions. In versions 0.261.003 and 0.261.027, an authorization ordering flaw in POST /api/user/plugins allows an authenticated low-privileged user to omit the top-level MCP type so that _reject_non_admin_mcp_stdio skips inspection before the type is restored from metadata. The stored personal action can then reach McpPluginFactory.create_connector, and MCPStdioPlugin.connect starts the attacker-selected operating-system process under the application service identity when the action tool is invoked. Exploitation requires personal plugins to be enabled and governance to permit MCP actions, and it can expose or modify secrets and data available to the service or disrupt the service. This issue is fixed in version 0.261.031.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-78",
        "CWE-863"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/105xxx/CVE-2026-105797.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "fixed": "0.261.031"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/microsoft/simplechat

Affected ranges

Type
GIT
Repo
https://github.com/microsoft/simplechat
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source": "REFERENCES"
}

Affected versions

0.*
0.190.1
0.190.3
0.202.37
0.202.41
v0.*
v0.179.group_documents.13
v0.185.0
v0.185.1
v0.191.0
v0.196.9
v0.199.3
v0.201.5
v0.202.21
v0.203.15
v0.203.16
v0.212.078
v0.212.079
v0.212.091
v0.213.001
v0.213.003
v0.214.001
v0.215.34
v0.215.35
v0.215.36
v0.215.37
v0.215.38
v0.229.001

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-105797.json"