CVE-2026-0757General

LOWCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

MCP Manager for Claude Desktop execute-command Command Injection Sandbox Escape Vulnerability. This vulnerability allows remote attackers to bypass the sandbox on affected installations of MCP Manager for Claude Desktop. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of MCP config objects. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to escape the sandbox and execute arbitrary code in the context of the current process at medium integrity. Was ZDI-CAN-27810.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 3d ago at 1 mentions (2026-01-28); latest day: 1
  • 4 total mentions across 4 days

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-01-28: 1Mentions · 2026-02-04: 1Mentions · 2026-03-06: 1Mentions · 2026-03-07: 1PoC Mentioned / Linked · 2026-01-28: 1Patch / Workaround · 2026-03-06: 1Technical Details · 2026-01-28: 1Technical Details · 2026-02-04: 1Technical Details · 2026-03-06: 101-2802-0403-0603-07
Signal classification3 categories
General
250.0%
Disclosure
125.0%
Patch
125.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-01-281
Disclosure1
2026-02-041
General1
2026-03-061
Patch1
2026-03-071
General1
Full discourse4 posts
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2023-20198 2 - CVE-2023-50428 3 - CVE-2026-0757 4 - CVE-2024-23225 5 - CVE-2026-20700 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post simply lists five trending CVEs with no additional security information provided.

    00010158
    1.7K followersView on X
  • Grok@grok
    Patch

    Yes, the Feb 2026 reports (including LayerX's zero-click RCE via Google Calendar in Desktop Extensions and CVE-2026-0757 in MCP Manager) apply directly to Claude Desktop on macOS when using MCP features/servers/extensions. These run unsandboxed with full system access on Mac, enabling sandbox escapes, command injection, and potential takeover via malicious repos or invites. Privacy retention issues also persist. Use the web version or official patches only. What specific MCP tool were you testing?

    Post summary

    The post highlights vulnerabilities in Claude Desktop’s MCP components and emphasizes the use of official patches or the web version as a mitigation strategy.

    1000060
    8.4M followersView on X
  • Giuliano F.@giulianofalco
    General

    MCP Manager RCE (CVE-2026-0757) ist der beste Beweis: Wer AI-Agents ohne Hardening auf sein System lässt, hat die Kontrolle über seine Sandbox verloren. 🔒 Vulnerability Management ist kein optionales Feature, es ist das Fundament. 🧵

    Post summary

    The tweet notes a remote code execution flaw (CVE‑2026‑0757) in MCP Manager and stresses the need to harden AI agents, but it offers no PoC, exploit code, patch, or active exploitation evidence.

    0000053
    58 followersView on X
  • TheZDIBugs@TheZDIBugs
    Disclosure

    [ZDI-26-023|CVE-2026-0757] (0Day) MCP Manager for Claude Desktop execute-command Command Injection Sandbox Escape Vulnerability (CVSS 8.8; Credit: Peter Girnus (@gothburz), Brandon Niemczyk of Trend Zero Day Initiative) https://www.zerodayinitiative.com/advisories/ZDI-26-023/

    Post summary

    Zero-Day advisory for CVE-2026-0757, describing a command‑injection vulnerability in MCP Manager for Claude Desktop (CVSS 8.8), with a PoC link but no patch, active exploitation, or false‑positive claim.

    00000552
    5.3K followersView on X

Explore more