CVE-2026-5602Disclosure

LOWCVSS 1.9 · LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was determined in Nor2-io heim-mcp up to 0.1.3. Impacted is the function registerTools of the file src/tools.ts of the component new_heim_application/deploy_heim_application/deploy_heim_application_to_cloud. This manipulation causes os command injection. The attack requires local access. The exploit has been publicly disclosed and may be utilized. Patch name: c321d8af25f77668781e6ccb43a1336f9185df37. It is suggested to install a patch to address this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked 2d ago at 2 mentions (2026-04-05); latest day: 1
  • 5 total mentions across 3 days

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-04-05: 2Mentions · 2026-04-06: 2Mentions · 2026-04-07: 1Technical Details · 2026-04-06: 204-0504-0604-07
Signal classification2 categories
Disclosure
360.0%
General
240.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-052
Disclosure2
2026-04-062
Disclosure1General1
2026-04-071
General1
Full discourse5 posts
  • Nick Stocks@mistaike_ai
    General

    We’re seeing CVEs like CVE-2026-26981, CVE-2026-5602, and CVE-2026-5603 already flagged by our one-day scanner before most teams even notice them. Here’s the uncomfortable truth: Some of these aren’t sophisticated breaches. They’re basic failures. 🧵

    Post summary

    The post highlights that a rapid scanner has flagged several new CVEs before many teams notice them, but provides no further technical or exploit information.

    1000041
    6 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-5602 - Nor2-io heim-mcp new_heim_application tools.ts registerTools os command injection Intel Report: https://ift.tt/239GIOR

    Post summary

    The tweet announces a newly identified command‑injection vulnerability (CVE‑2026‑5602) associated with the Nor2‑io heim‑mcp application, offering only a brief technical description and an Intel Report link without concrete POCs, exploit code, or patch information.

    0000035
    281 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-5602 - Nor2-io heim-mcp new_heim_application tools.ts registerTools os command injection Intel Report: https://ift.tt/bOEY4Z8

    Post summary

    The post announces a new CVE (2026-5602) describing an OS command injection flaw, but provides no evidence of PoC, exploit code, active exploitation, or remediation.

    0000042
    281 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-5602 A vulnerability was determined in Nor2-io heim-mcp up to 0.1.3. Impacted is the function registerTools of the file src/tools.ts of the component new_heim_application/de… https://www.cve.org/CVERecord?id=CVE-2026-5602 ----- Traducción: CVE-2026-5602 Se … http://infoflow.cloud`

    Post summary

    The text announces CVE-2026-5602 in Nor2-io heim-mcp, noting the affected component but providing minimal technical detail.

    0000043
    63 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5602 A vulnerability was determined in Nor2-io heim-mcp up to 0.1.3. Impacted is the function registerTools of the file src/tools.ts of the component new_heim_application/de… https://www.cve.org/CVERecord?id=CVE-2026-5602

    Post summary

    The post announces CVE‑2026‑5602 affecting Nor2‑io heim‑mcp up to v0.1.3, naming the impacted function "registerTools," but offers no details on exploitation, patches, or severity.

    00000577
    56.8K followersView on X

Explore more