CVE-2026-7061Disclosure

LOWCVSS 5.5 · MEDIUM

Exploit discussion active in current signal (4 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A weakness has been identified in Toowiredd chatgpt-mcp-server up to 0.1.0. Affected by this issue is some unknown functionality of the file src/services/docker.service.ts of the component MCP/HTTP. This manipulation causes os command injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • Exploit: 1 classified signal
  • Peaked at 4 mentions on most recent observed day (2026-05-23)
  • 5 total mentions across 2 days

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-04-26: 1Mentions · 2026-05-23: 4PoC Mentioned / Linked · 2026-05-23: 2Technical Details · 2026-04-26: 1Technical Details · 2026-05-23: 404-2605-23
Signal classification3 categories
Disclosure
360.0%
Exploit
120.0%
PoC
120.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-04-261
Disclosure1
2026-05-234
Disclosure2Exploit1PoC1
Full discourse5 posts
  • Lyrie.ai@lyrie_ai
    Disclosure

    What Happened On April 26, 2026, security researchers disclosed CVE-2026-7061 affecting the chatgpt-mcp-server project (Toowiredd). The flaw exists in src/services/docker.service.ts, a component designed to bridge Model Context Protocol (MCP) servers with Docker container…

    Post summary

    Security researchers disclosed CVE-2026-7061 affecting the chatgpt-mcp-server, pointing to a flaw in its Docker integration component. No PoC, exploit, active use, mitigation, or debunking details appear in the text.

    2000048
    227 followersView on X
  • Lyrie.ai@lyrie_ai
    PoC

    Sources TheHackerWire: CVE-2026-7061 GitHub: Toowiredd/chatgpt-mcp-server GitHub Issue #8: Command Injection Report Public Exploit PoC VulDB: CVE-2026-7061 NVD: CVE-2026-7061

    Post summary

    The information focuses on the public proof‑of‑concept for CVE‑2026‑7061 and a GitHub repository, with no details on active exploitation, patches, or false‑positive claims.

    10000360
    227 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    77 Improper — MCP Server Weaponized: ChatGPT-MCP Command Injection Puts AI Agent Infrastructure at Risk. TL;DR A critical command injection vulnerability (CVE-2026-7061, CVSS 7.3) discovered in Toowiredd's chatgpt-mcp-server allows unauthenticated attackers to achieve…

    Post summary

    The text announces a critical command injection flaw (CVE-2026-7061) in Toowiredd’s chatgpt-mcp-server with high CVSS but provides no evidence of active exploitation or PoC.

    1000052
    227 followersView on X
  • Lyrie.ai@lyrie_ai
    Exploit

    TL;DR A critical command injection vulnerability (CVE-2026-7061, CVSS 7.3) discovered in Toowiredd's chatgpt-mcp-server allows unauthenticated attackers to achieve remote code execution via the Docker service component. The exploit is already public, the project is…

    Post summary

    A critical command injection vulnerability (CVE‑2026‑7061, CVSS 7.3) in Toowiredd's chatgpt‑mcp‑server enables unauthenticated remote code execution via Docker; a public exploit already exists, but no active exploitation or patch has been reported.

    1000054
    227 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-7061 A weakness has been identified in Toowiredd chatgpt-mcp-server up to 0.1.0. Affected by this issue is some unknown functionality of the file src/services/docker.service… https://www.cve.org/CVERecord?id=CVE-2026-7061

    Post summary

    A weakness in Toowiredd chatgpt-mcp-server up to v0.1.0 affecting the docker.service file has been identified and filed as CVE-2026-7061.

    0000065
    57.3K followersView on X

Explore more