GHSA-86hp-qxqp-w9wv

Suggest an improvement
Source
https://github.com/advisories/GHSA-86hp-qxqp-w9wv
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-86hp-qxqp-w9wv/GHSA-86hp-qxqp-w9wv.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-86hp-qxqp-w9wv
Aliases
Published
2026-04-30T00:31:22Z
Modified
2026-05-06T23:41:28Z
Severity
  • 7.3 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L CVSS Calculator
  • 5.5 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
mcp-server-semgrep has a Command Injection issue
Details

A vulnerability was detected in VetCoders mcp-server-semgrep 1.0.0. This affects the function analyze_results/filter_results/export_results/compare_results/scan_directory/create_rule of the file src/index.ts of the component MCP Interface. The manipulation of the argument ID results in os command injection. The attack can be executed remotely. The exploit is now public and may be used. Upgrading to version 1.0.1 is able to mitigate this issue. The patch is identified as 141335da044e53c3f5b315e0386e01238405b771. It is advisable to upgrade the affected component.

Database specific
{
    "cwe_ids":  [
        "CWE-77"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-05-06T23:28:35Z",
    "nvd_published_at":  "2026-04-30T00:16:23Z",
    "severity":  "MODERATE"
}
References

Affected packages

npm / mcp-server-semgrep

Package

Name
mcp-server-semgrep
View open source insights on deps.dev
Purl
pkg:npm/mcp-server-semgrep

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.0.1

Database specific

last_known_affected_version_range
"<= 1.0.0"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-86hp-qxqp-w9wv/GHSA-86hp-qxqp-w9wv.json"