GHSA-2g7v-hghf-grg4

Suggest an improvement
Source
https://github.com/advisories/GHSA-2g7v-hghf-grg4
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-2g7v-hghf-grg4/GHSA-2g7v-hghf-grg4.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-2g7v-hghf-grg4
Aliases
Published
2026-02-08T03:30:27Z
Modified
2026-02-10T00:41:26.086621Z
Severity
  • 6.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L CVSS Calculator
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
mcp-maigret vulnerable to command injection
Details

A vulnerability was determined in BurtTheCoder mcp-maigret up to 1.0.12. This affects an unknown part of the file src/index.ts of the component search_username. Executing a manipulation of the argument Username can lead to command injection. The attack may be launched remotely. Upgrading to version 1.0.13 is able to mitigate this issue. This patch is called b1ae073c4b3e789ab8de36dc6ca8111ae9399e7a. Upgrading the affected component is advised.

Database specific
{
    "github_reviewed_at": "2026-02-10T00:22:25Z",
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-74",
        "CWE-77"
    ],
    "nvd_published_at": "2026-02-08T03:15:46Z",
    "severity": "MODERATE"
}
References

Affected packages

npm / mcp-maigret

Package

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.0.13

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-2g7v-hghf-grg4/GHSA-2g7v-hghf-grg4.json"