CVE-2026-5528 identifies an OS command injection vulnerability within the HTTP Interface of MoussaabBadla code-screenshot-mcp up to version 0.1.0. This medium-severity flaw (CVSS 6.3) allows a remote attacker with low privileges and low attack complexity to execute arbitrary commands, resulting in low impact to confidentiality, integrity, and availability. The exploit has been publicly disclosed and is on the "Hot List," indicating its potential for use. While not yet observed in active exploitation (CISA KEV) and lacking public exploit modules, there is limited community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| MoussaabBadla | Code-Screenshot-Mcp | 0.1.0CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.