CVE-2026-3484General(phialsbasement / mcp_nmap_server)

MEDIUMCVSS 8.8 · HIGH

Exploitation observed; activity peaked at 4 mentions and remains active

Immediate actions

  • Patch phialsbasement mcp_nmap_server systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

A vulnerability was detected in PhialsBasement nmap-mcp-server up to bee6d23547d57ae02460022f7c78ac0893092e38. Affected by this issue is the function child_process.exec of the file src/index.ts of the component Nmap CLI Command Handler. The manipulation results in command injection. The attack may be performed from remote. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The patch is identified as 30a6b9e1c7fa6146f51e28d6ab83a2568d9a3488. It is best practice to apply a patch to resolve this issue.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-77

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mcp_nmap_server

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 9 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 7 signals
  • General: 4 classified signals
  • Disclosure: 3 classified signals
  • Peaked 3d ago at 4 mentions (2026-03-03); latest day: 1
  • 9 total mentions across 4 days

Affected systems

Products
mcp_nmap_server

Deep dive

Activity timeline9 mentions / 4d
01234Mentions · 2026-03-03: 4Mentions · 2026-03-04: 1Mentions · 2026-03-06: 3Mentions · 2026-04-21: 1Active Exploitation · 2026-03-04: 1Patch / Workaround · 2026-03-06: 1Technical Details · 2026-03-03: 2Technical Details · 2026-03-04: 1Technical Details · 2026-03-06: 3Technical Details · 2026-04-21: 103-0303-0403-0604-21
Signal classification4 categories
General
444.4%
Disclosure
333.3%
Active Exploitation
111.1%
Patch
111.1%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-034
Disclosure1General3
2026-03-041
Active Exploitation1
2026-03-063
Disclosure1General1Patch1
2026-04-211
Disclosure1
Full discourse9 posts
  • ナタリー 🌙@Absolcasso
    Patch

    @luckyPipewrench @zaimiri Exactly. CVE-2026-3484 in nmap-mcp-server and CVE-2026-27825 in mcp-atlassian were patched, but the architecture that lets injected payloads ride MCP responses is still there. One CVE at a time is the wrong unit of analysis.

    Post summary

    The author notes that CVE-2026-3484 and CVE-2026-27825 have been patched, yet the architectural flaw allowing payloads in MCP responses still exists, suggesting a broader systemic issue.

    1002045
    68 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3484 A vulnerability was detected in PhialsBasement nmap-mcp-server up to bee6d23547d57ae02460022f7c78ac0893092e38. Affected by this issue is the function child_process.exec… https://www.cve.org/CVERecord?id=CVE-2026-3484

    Post summary

    A new vulnerability (CVE-2026-3484) has been identified in PhialsBasement nmap-mcp-server, targeting the child_process.exec function, but no exploit code, patch, or evidence of active exploitation is provided.

    00020165
    56.6K followersView on X
  • ナタリー 🌙@Absolcasso
    General

    ecting.We're seeing a severe lag between AI capabilities and MCP security. Between the RCE flaw in nmap-mcp-server (CVE-2026-3484) and Anthropic's Git server flaw (CVE-2026-25710), we can't blindly trust 3rd-party tools. Always scan MCP servers before connecting.

    Post summary

    The text lists two CVEs with an RCE designation and advises scanning MCP servers, but provides no PoC, exploitation details, or patch information.

    0001056
    69 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-3484 Remote Command Injection in PhialsBasement nmap-mcp-server via CLI Command Handler https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3484

    Post summary

    The text simply lists CVE‑2026‑3484 with a one‑line description of a Remote Command Injection flaw and provides a link to vulnerability details, offering no further actionable information.

    0001052
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-3484 A vulnerability was detected in PhialsBasement nmap-mcp-server up to bee6d23547d57ae02460022f7c78ac0893092e38. Affected by this issue is the function child_process.exec… https://www.cve.org/CVERecord?id=CVE-2026-3484 ----- Traducción: CVE-2026-3484 Se … http://infoflow.cloud`

    Post summary

    The post references CVE-2026-3484 affecting PhialsBasement nmap-mcp-server, noting the child_process.exec function is impacted, but provides no further details on exploitation, patching, or technical depth.

    0001036
    55 followersView on X
  • Jasper@Tristin_0a
    Disclosure

    CVE-2026-3484 + CVE-2026-25710: MCP Server 接连爆出 RCE 漏洞。你的 agent 有多少无审批写操作?MCP 审批护栏包 = 白名单+审批+回滚+审计。首单试单 0.0052 USDT/call。回复「首单试单」或 DM workflow,15分钟回样例。#MCP #EnterpriseAI

    Post summary

    The post announces that MCP Server has two new RCE vulnerabilities (CVE-2026-3484 and CVE-2026-25710) and offers a priced test service, but it provides no PoC, exploit code, patch information, or evidence of active exploitation.

    0000032
    173 followersView on X
  • ナタリー 🌙@Absolcasso
    Disclosure

    CVE-2026-3484。nmap-mcp-serverがshell入力をchild_process.execにそのまま渡していた。細工されたターゲット文字列でホスト上の任意コード実行。サニタイズなしのMCPツール入力がどれだけ危険か、理論じゃなく実例として出てきてる。

    Post summary

    The text discloses that CVE-2026-3484 allows arbitrary code execution in nmap-mcp-server due to unsanitized shell input passed to child_process.exec.

    00000235
    68 followersView on X
  • ナタリー 🌙@Absolcasso
    Active Exploitation

    CVE-2026-3484: nmap-mcp-server passes shell input directly to child_process.exec. A crafted target string triggers arbitrary RCE on the host. This is what unsanitized MCP tool input looks like not theoretical, already in the wild.

    Post summary

    The text reports that CVE-2026-3484, an RCE in nmap-mcp-server due to unsanitized input via child_process.exec, is actively being exploited in the wild.

    0000046
    69 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-3484 Intel Report: https://ift.tt/siL9IvV

    Post summary

    The text announces CVE‑2026‑3484 and provides a link to an Intel Report but offers no details on exploitation, patches, or technical specifics.

    0000031
    342 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appphialsbasementmcp_nmap_server---

Explore more