
[ZDI-26-022|CVE-2026-0756] (0Day) github-kanban-mcp-server execAsync Command Injection Remote Code Execution Vulnerability (CVSS 9.8; Credit: Brandon Niemczyk & Peter Girnus (@gothburz) of Trend Zero Day Initiative) https://www.zerodayinitiative.com/advisories/ZDI-26-022/
Post summary
A newly discovered CVE-2026-0756 zero‑day RCE vulnerability in github-kanban-mcp-server is disclosed with a high CVSS score of 9.8; no patch or exploit tool is mentioned.
