CVE-2026-25546 describes a command injection vulnerability in Godot MCP, a Model Context Protocol server for the Godot game engine, affecting versions prior to 0.1.1. This flaw allows remote code execution due to the 'executeOperation' function directly passing user-controlled input, such as 'projectPath', to the 'exec()' function, which spawns a shell. An attacker could inject shell metacharacters to execute arbitrary commands with the privileges of the MCP server. The vulnerability is rated as HIGH severity (CVSS 7.8), indicating a low attack complexity and no required privileges, though user interaction is required. A successful exploit could lead to complete compromise of confidentiality, integrity, and availability of the affected system. Currently, there is no evidence of active exploitation, and no public exploit code or Metasploit/Nuclei modules are available. Community discussion and media coverage for this CVE are minimal, which is typical for the vast majority of reported vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.1.1CPE matchmatch criteria | cpe:2.3:a:coding-solo:godot_mcp:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.