CVE-2026-5528General

LOWCVSS 2.1 · LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A security vulnerability has been detected in MoussaabBadla code-screenshot-mcp up to 0.1.0. This affects an unknown part of the component HTTP Interface. Such manipulation leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 3 classified signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-04-05); latest day: 1
  • 5 total mentions across 3 days

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-04-04: 1Mentions · 2026-04-05: 3Mentions · 2026-04-13: 1Patch / Workaround · 2026-04-13: 1Technical Details · 2026-04-05: 104-0404-0504-13
Signal classification3 categories
General
360.0%
Disclosure
120.0%
Patch
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-041
General1
2026-04-053
Disclosure1General2
2026-04-131
Patch1
Full discourse5 posts
  • Abcas MCP Guard@abcas_mcp_guard
    Patch

    Security isn't just about static scans. CVE-2026-5833 and CVE-2026-5528 in community MCP servers prove that "trusted" code can still have injection risks. Production agents need execution-time authorization to block bad calls before they happen. 🛡️ #MCPSecurity #AIAgents #MCP

    Post summary

    The statement highlights injection vulnerabilities in MCP servers (CVE‑2026‑5833 and CVE‑2026‑5528) and recommends that production agents enforce execution‑time authorization as a mitigation.

    1000043
    11 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-5528 📊 Severity: 6.3 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-5528 #CVE-2026-5528 #CVE #Medium #CyberSecurity #InfoSec https://t.co/6xkEVeXCMZ

    Post summary

    The tweet announces CVE-2026-5528 with a severity of 6.3 and links to the NVD, but provides no additional details such as exploits, patches, or technical information.

    0000033
    121 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-5528 - MoussaabBadla code-screenshot-mcp HTTP os command injection Intel Report: https://ift.tt/SHcwj8Q

    Post summary

    The alert identifies CVE‑2026‑5528 as an HTTP OS command injection vulnerability, but does not provide PoC, exploit code, active exploitation evidence, or patch information.

    0000041
    281 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-5528 A security vulnerability has been detected in MoussaabBadla code-screenshot-mcp up to 0.1.0. This affects an unknown part of the component HTTP Interface. Such manipula… https://www.cve.org/CVERecord?id=CVE-2026-5528 ----- Traducción: CVE-2026-5528 Se … http://infoflow.cloud`

    Post summary

    The post confirms CVE‑2026‑5528 exists in the specified component but provides no further technical, exploit, or mitigation details.

    0000041
    63 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-5528 A security vulnerability has been detected in MoussaabBadla code-screenshot-mcp up to 0.1.0. This affects an unknown part of the component HTTP Interface. Such manipula… https://www.cve.org/CVERecord?id=CVE-2026-5528

    Post summary

    The post merely flags that CVE‑2026‑5528 has been detected in MoussaabBadla code‑screenshot‑mcp, offering no evidence of exploitation, PoC, or remediation.

    00000547
    57.0K followersView on X

Explore more