CVE-2026-26015Disclosure(arc53 / docsgpt)

LOWCVSS 9.8 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch arc53 docsgpt systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

DocsGPT is a GPT-powered chat for documentation. From version 0.15.0 to before version 0.16.0, an attacker accessing both the official DocsGPT website or any local and public deployment, can craft a malicious payload bypassing the "MCP test" behavior to achieve arbitrary remote code execution (RCE). This issue has been patched in version 0.16.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • docsgpt

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-05-11); latest day: 2
  • 7 total mentions across 5 days

Affected systems

Vendors
Products
docsgpt

1 version affected across 1 product

Deep dive

Activity timeline7 mentions / 5d
01122Mentions · 2026-04-29: 1Mentions · 2026-05-02: 1Mentions · 2026-05-04: 1Mentions · 2026-05-11: 2Mentions · 2026-06-05: 2Patch / Workaround · 2026-06-05: 2Technical Details · 2026-05-04: 1Technical Details · 2026-05-11: 1Technical Details · 2026-06-05: 104-2905-0205-0405-1106-05
Signal classification3 categories
Disclosure
342.9%
General
342.9%
Patch
114.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-04-291
Disclosure1
2026-05-021
General1
2026-05-041
Disclosure1
2026-05-112
General2
2026-06-052
Disclosure1Patch1
Full discourse7 posts
  • Lyrie.ai@lyrie_ai
    Disclosure

    Six live production platforms were compromised during responsible disclosure testing. LiteLLM (CVE-2026-30623, Critical, patched), Windsurf (CVE-2026-30615, Critical, reported), Bisheng (CVE-2026-33224, Critical, patched), and DocsGPT (CVE-2026-26015, Critical, patched)…

    Post summary

    The excerpt reports that several production platforms were compromised during responsible disclosure testing, lists CVEs with a "Critical" severity, and notes that most have been patched, but offers no PoC, exploit code, or detailed technical description.

    1000046
    246 followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    Immediate (0-48h): Patch all MCP-connected platforms against the OX Security CVE list: priority CVE-2026-30615 (zero-click Windsurf), CVE-2026-30623 (LiteLLM authenticated RCE), CVE-2026-26015 (DocsGPT MITM) Block public IP access to all LLM/AI enabler services; restrict…

    Post summary

    The advisory prioritizes patching MCP-connected platforms for CVE-2026-30615, CVE-2026-30623, and CVE-2026-26015 to mitigate zero-click, authenticated RCE, and MITM vulnerabilities.

    1000063
    246 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    Unpopular opinion: The cybersecurity industry is selling you dashboards. CVE: CVE-2026-26015 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The tweet simply lists CVE-2026-26015 with its CVSS score and critical status, offering no further context on exploitation, mitigation, or remediation.

    1000028
    197 followersView on X
  • z3n@zench4n
    Disclosure

    Recent trends show a rise in vulnerabilities like CVE-2026-26015 in DocsGPT. When an agent can read documentation, a prompt injection can turn that access into a path traversal attack, allowing the agent to leak sensitive system files.

    Post summary

    The post highlights a newly disclosed DocsGPT vulnerability (CVE‑2026‑26015) that allows path traversal through prompt injection, without mentioning exploits, patches, or active attacks.

    1000027
    1.4K followersView on X
  • z3n@zench4n
    General

    Take DocsGPT (CVE-2026-26015) as a lesson. When RAG systems ingest documentation, the boundary between retrieved context and system instructions blurs. Deep dive analysis must focus on how LLM outputs influence downstream shell commands or file system access.

    Post summary

    The statement cites CVE-2026-26015 as a cautionary example of blending retrieval context with system instructions in RAG systems but offers no concrete technical, exploitative, or mitigative details.

    1000033
    1.4K followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-26015-arc53-docsgpt #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The tweet cites a research article about CVE-2026-26015 but provides no concrete details regarding exploitation, patches, or technical aspects.

    0000017
    188 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-26015 DocsGPT is a GPT-powered chat for documentation. From version 0.15.0 to before version 0.16.0, an attacker accessing both the official DocsGPT website or any local an… https://www.cve.org/CVERecord?id=CVE-2026-26015

    Post summary

    The snippet references CVE‑2026‑26015 impacting DocsGPT versions 0.15.0 through 0.15.x, but provides no additional exploit, patch, or technical detail.

    0000096
    57.3K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apparc53docsgpt0.15.0--

Explore more