CVE-2026-4192 is a medium-severity command injection vulnerability found in AvinashBole quip-mcp-server version 1.0.0, specifically within the setupToolHandlers function of src/index.ts. This flaw allows a remote attacker with low privileges to execute arbitrary commands, potentially leading to limited impact on confidentiality, integrity, and availability. The CVSS score is 6.3, indicating a network attack vector with low complexity and no user interaction required. Although the project maintainers have been notified, they have not yet responded to the issue. Public exploit code for this vulnerability has been disclosed, but there is currently no evidence of active exploitation, nor significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| AvinashBole | Quip-Mcp-Server | 1.0.0CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.