CVE-2026-30625

Source
https://cve.org/CVERecord?id=CVE-2026-30625
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-30625.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-30625
Aliases
Published
2026-04-15T00:00:00Z
Modified
2026-07-15T01:48:59.353341071Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Upsonic 0.71.6 contains a remote code execution vulnerability in its MCP server/task creation functionality. The application allows users to define MCP tasks with arbitrary command and args values. Although an allowlist exists, certain allowed commands (npm, npx) accept argument flags that enable execution of arbitrary OS commands. Maliciously crafted MCP tasks may lead to remote code execution with the privileges of the Upsonic process. In version 0.72.0 Upsonic added a warning about using Stdio servers being able to execute commands directly on the machine.

Database specific
{
    "cna_assigner": "mitre",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/30xxx/CVE-2026-30625.json"
}
References

Affected packages

Git / github.com/upsonic/upsonic

Affected ranges

Type
GIT
Repo
https://github.com/upsonic/upsonic
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "source": "REFERENCES"
}

Affected versions

v0.*
v0.1.0
v0.1.1
v0.1.2
v0.10.0
v0.11.0
v0.12.0
v0.13.0
v0.14.0
v0.14.2
v0.14.5
v0.15.0
v0.16.0
v0.16.2
v0.16.3
v0.16.4
v0.16.5
v0.16.6
v0.16.7
v0.17.0
v0.18.0
v0.18.1
v0.18.2
v0.19.0
v0.19.1
v0.2.0
v0.20.0
v0.21.0
v0.21.1
v0.22.0
v0.22.1
v0.22.2
v0.22.3
v0.23.0
v0.23.1
v0.23.10
v0.23.11
v0.23.12
v0.23.13
v0.23.14
v0.23.15
v0.23.16
v0.23.17
v0.23.18
v0.23.19
v0.23.2
v0.23.20
v0.23.21
v0.23.22
v0.23.23
v0.23.24
v0.23.25
v0.23.26
v0.23.27
v0.23.3
v0.23.4
v0.23.5
v0.23.6
v0.23.7
v0.23.8
v0.23.9
v0.24.0
v0.24.1
v0.24.10
v0.24.11
v0.24.12
v0.24.13
v0.24.14
v0.24.15
v0.24.16
v0.24.17
v0.24.18
v0.24.19
v0.24.2
v0.24.20
v0.24.21
v0.24.22
v0.24.23
v0.24.24
v0.24.25
v0.24.26
v0.24.27
v0.24.28
v0.24.29
v0.24.3
v0.24.30
v0.24.31
v0.24.32
v0.24.33
v0.24.4
v0.24.5
v0.24.6
v0.24.7
v0.24.8
v0.24.9
v0.25.0
v0.25.1
v0.25.2
v0.26.0
v0.26.1
v0.26.10
v0.26.11
v0.26.2
v0.26.3
v0.26.4
v0.26.5
v0.26.6
v0.26.7
v0.26.8
v0.26.9
v0.27.0
v0.27.1
v0.27.10
v0.27.2
v0.27.3
v0.27.4
v0.27.5
v0.27.6
v0.27.7
v0.27.8
v0.27.9
v0.28.0
v0.28.1
v0.28.2
v0.28.3
v0.3.0
v0.36.0
v0.37.0
v0.38.0
v0.38.1
v0.39.0
v0.4.0
v0.40.0
v0.40.1
v0.40.2
v0.40.3
v0.40.4
v0.40.5
v0.40.6
v0.40.7
v0.41.0
v0.41.1
v0.42.0
v0.43.0
v0.44.0
v0.44.1
v0.44.2
v0.45.0
v0.45.1
v0.45.2
v0.45.3
v0.45.4
v0.46.0
v0.46.1
v0.47.0
v0.47.1
v0.47.2
v0.47.3
v0.47.4
v0.47.5
v0.48.0
v0.49.0
v0.5.0
v0.5.1
v0.5.4
v0.5.5
v0.5.6
v0.50.0
v0.50.1
v0.50.2
v0.50.3
v0.50.4
v0.50.5
v0.51.0
v0.51.1
v0.51.2
v0.52.0
v0.52.1
v0.52.2
v0.52.3
v0.52.4
v0.53.0
v0.53.1
v0.54.0
v0.55.0
v0.55.1
v0.55.2
v0.55.3
v0.55.4
v0.55.5
v0.55.6
v0.56.0
v0.56.1
v0.57.0
v0.58.0
v0.59.0
v0.59.1
v0.59.10
v0.59.11
v0.59.2
v0.59.3
v0.59.4
v0.59.5
v0.59.6
v0.59.7
v0.59.8
v0.59.9
v0.6.0
v0.6.1
v0.6.11
v0.6.12
v0.6.13
v0.6.14
v0.6.2
v0.6.3
v0.6.6
v0.6.7
v0.6.8
v0.60.0
v0.61.0
v0.61.1
v0.62.0
v0.63.0
v0.64.0
v0.64.1
v0.65.0
v0.65.1
v0.66.0
v0.66.1
v0.67.0
v0.67.1
v0.67.2
v0.67.3
v0.67.4
v0.68.0
v0.68.1
v0.68.2
v0.68.3
v0.69.0
v0.69.1
v0.69.2
v0.69.3
v0.7.0
v0.7.1
v0.70.0
v0.71.0
v0.71.1
v0.71.2
v0.71.3
v0.71.4
v0.71.5
v0.71.6
v0.8.0
v0.8.2
v0.8.3
v0.8.4
v0.8.7
v0.8.8
v0.8.9
v0.9.0
v0.9.1
v0.9.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-30625.json"