CVE-2026-5602 is an OS command injection vulnerability identified in Nor2-io heim-mcp versions up to 0.1.3, specifically within the registerTools function of src/tools.ts. The flaw affects the new heim application and cloud deployment components, allowing attackers to execute arbitrary system commands through the vulnerable function. The vulnerability carries a CVSS v3.1 score of 5.3 (Medium severity), with a local attack vector requiring low complexity and user privileges but no interaction. The impact is limited to confidentiality, integrity, and availability at the local level. The EPSS score of 0.0008 indicates this vulnerability is not currently widespread among exploited CVEs in the wild. Exploitation currently requires local access to the affected system. While the vulnerability has been publicly disclosed, there is no evidence of active exploitation, and the vulnerability does not appear on the Known Exploited Vulnerabilities catalog. The vendor responded professionally and released a patched version (commit c321d8af25f77668781e6ccb43a1336f9185df37), and organizations should prioritize upgrading to the fixed version to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Nor2-Io | Heim-Mcp | 0.1.0, 0.1.1, 0.1.2, 0.1.3CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.