CVE-2026-5833Disclosure

LOWCVSS 1.9 · LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A security vulnerability has been detected in awwaiid mcp-server-taskwarrior up to 1.0.1. This impacts the function server.setRequestHandler of the file index.ts. Such manipulation of the argument Identifier leads to command injection. The attack must be carried out locally. The exploit has been disclosed publicly and may be used. The name of the patch is 1ee3d282debfa0a99afeb41d22c4b2fd5a3148f2. Applying a patch is advised to resolve this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-77

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 4 classified signals
  • Peaked 2d ago at 2 mentions (2026-04-09); latest day: 1
  • 4 total mentions across 3 days

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-04-09: 2Mentions · 2026-04-10: 1Mentions · 2026-04-13: 1Patch / Workaround · 2026-04-13: 1Technical Details · 2026-04-09: 204-0904-1004-13
Signal classification1 categories
Disclosure
4100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-092
Disclosure2
2026-04-101
Disclosure1
2026-04-131
Disclosure1
Full discourse4 posts
  • Abcas MCP Guard@abcas_mcp_guard
    Disclosure

    Security isn't just about static scans. CVE-2026-5833 and CVE-2026-5528 in community MCP servers prove that "trusted" code can still have injection risks. Production agents need execution-time authorization to block bad calls before they happen. 🛡️ #MCPSecurity #AIAgents #MCP

    Post summary

    The post highlights that two new CVEs in community MCP servers expose injection risks, emphasizing the need for runtime authorization as a mitigation.

    1000043
    11 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-5833 📊 Severity: 5.3 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-5833 #CVE-2026-5833 #CVE #Medium #CyberSecurity #InfoSec https://t.co/eZKpBkr3f6

    Post summary

    The tweet announces CVE‑2026‑5833, states its severity (5.3) and medium risk, and provides a link to the NVD record, but gives no evidence of exploitation, PoC, or patch.

    0000028
    123 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-5833 A security vulnerability has been detected in awwaiid mcp-server-taskwarrior up to 1.0.1. This impacts the function server.setRequestHandler of the file index.ts. Such … https://www.cve.org/CVERecord?id=CVE-2026-5833 ----- Traducción: CVE-2026-5833 Se … http://infoflow.cloud`

    Post summary

    The entry announces CVE-2026-5833, a vulnerability in awwaiid mcp-server-taskwarrior that affects server.setRequestHandler in index.ts, without supplying PoC, exploit details, or patches.

    0000037
    67 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5833 A security vulnerability has been detected in awwaiid mcp-server-taskwarrior up to 1.0.1. This impacts the function server.setRequestHandler of the file index.ts. Such … https://www.cve.org/CVERecord?id=CVE-2026-5833

    Post summary

    A CVE-2026-5833 vulnerability was identified in awwaiid mcp-server-taskwarrior up to 1.0.1, impacting the server.setRequestHandler function in index.ts, but no PoC, exploit, patch, or active exploitation information is provided.

    00000241
    57.0K followersView on X

Explore more