CVE-2026-2178 is a critical command injection vulnerability affecting r-huijts xcode-mcp-server, specifically within the registerXcodeTools function of the src/tools/xcode/index.ts file. This flaw allows for remote command injection through the manipulation of the 'args' argument, enabling attackers to execute arbitrary commands. With a CVSS score of 8.8 (HIGH), the vulnerability is easily exploitable over the network with low attack complexity and no user interaction, leading to high impacts on confidentiality, integrity, and availability. Although not listed on KEV or Hot Lists, the exploit has been publicly disclosed, and community discussion and media coverage indicate significant attention, suggesting a heightened risk of exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2025-08-26CPE matchmatch criteria | cpe:2.3:a:r-huijts:xcode_mcp_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.