CVE-2025-9262 is a critical OS command injection vulnerability affecting wong2 mcp-cli version 1.13.0, specifically within the redirectToAuthorization function of the oAuth Handler component. This flaw allows for remote code execution with high impact on confidentiality, integrity, and availability. While the attack complexity is high and exploitability is difficult, a public exploit exists, though it is not currently listed in KEV or major exploit databases. Community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.13.0CPE matchmatch criteria | cpe:2.3:a:wong2:mcp-cli:1.13.0:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.