CVE-2026-5621Disclosure

LOWCVSS 1.9 · LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was found in ChrisChinchilla Vale-MCP up to 0.1.0. Affected by this vulnerability is an unknown functionality of the file src/index.ts of the component HTTP Interface. The manipulation of the argument config_path results in os command injection. Attacking locally is a requirement. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-04-06); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-06: 2Mentions · 2026-06-20: 1Technical Details · 2026-04-06: 1Technical Details · 2026-06-20: 104-0606-20
Signal classification1 categories
Disclosure
3100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-062
Disclosure2
2026-06-201
Disclosure1
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-56215 Capgo before 12.128.12 allows authenticated users to modify their mutable http://public.users.email to arbitrary addresses, which the SSO provisioning endpoint trusts as an … https://www.cve.org/CVERecord?id=CVE-2026-56215 ----- Traducción: CVE-2026-5621… http://infoflow.cloud`

    Post summary

    The tweet discloses a CVE-2026-56215 flaw in Capgo that allows authenticated users to change their public email address to arbitrary values, which the SSO provisioning endpoint trusts.

    0000080
    88 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-5621 A vulnerability was found in ChrisChinchilla Vale-MCP up to 0.1.0. Affected by this vulnerability is an unknown functionality of the file src/index.ts of the component … https://www.cve.org/CVERecord?id=CVE-2026-5621 ----- Traducción: CVE-2026-5621 Se … http://infoflow.cloud`

    Post summary

    The tweet briefly announces the existence of CVE-2026-5621, identifies the affected component and file, but provides no PoC, exploit, patch, or exploitation status.

    0000026
    67 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5621 A vulnerability was found in ChrisChinchilla Vale-MCP up to 0.1.0. Affected by this vulnerability is an unknown functionality of the file src/index.ts of the component … https://www.cve.org/CVERecord?id=CVE-2026-5621

    Post summary

    The post announces CVE-2026-5621, a vulnerability discovered in ChrisChinchilla Vale-MCP 0.1.0, affecting an unspecified functionality in src/index.ts.

    00000329
    57.0K followersView on X

Explore more