CVE-2026-102911

LOWCVSS 8.6 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw has been found in zosmaai pi-llm-wiki up to 0.11.7. Affected is an unknown function of the file mcp/index.ts of the component wiki_capture_source MCP tool. Executing a manipulation of the argument url can lead to os command injection. The attack can be executed remotely. The exploit has been published and may be used. Upgrading to version 0.11.8 is able to address this issue. This patch is called 360867034e79175b45c8e04a98e4ca712bbaca35. Upgrading the affected component is advised.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-09-30: 109-30
Referenced assets1 URL
Full discourse1 post
  • Security Arsenal, LLC@SecurityAr58409

    🔒 #CyberSecurity CVE-2026-102911, CVE-2026-103040, CVE-2026-103041: Critical LLM Infrastructure … "In the last 72 hours, NVD published three critical, network-vector vulnerabilities…" 🔗 https://securityarsenal.com/blog/cve-2026-102911-cve-2026-103040-cve-2026-103041-critical-llm-infrastructure-rce-detection-and-remediation-guide #CyberSecurity #ThreatIntel #cve2026102911 #critical #cve

    0000023
    35 followersView on X

Explore more