CVE-2026-7416Disclosure

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was found in PolarVista xcode-mcp-server 1.0.0. This issue affects the function build_project/run_tests of the file src/index.ts of the component MCP Interface. The manipulation of the argument Request results in os command injection. The attack may be launched remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 2d ago at 2 mentions (2026-04-29); latest day: 1
  • 4 total mentions across 3 days

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-04-29: 2Mentions · 2026-04-30: 1Mentions · 2026-05-02: 1Patch / Workaround · 2026-05-02: 1Technical Details · 2026-04-29: 1Technical Details · 2026-04-30: 1Technical Details · 2026-05-02: 104-2904-3005-02
Signal classification2 categories
Disclosure
250.0%
General
250.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-292
Disclosure1General1
2026-04-301
General1
2026-05-021
Disclosure1
Full discourse4 posts
  • Vito Botta@vitobotta
    Disclosure

    Command injection in MCP servers. Not surprised. CVE-2026-7446 hits mcp-server-semgrep, and CVE-2026-7416 hits xcode-mcp-server. Both let remote attackers inject OS commands with no auth needed. The attack surface on MCP servers keeps growing, and most of these community-built tools were never designed with security in mind. mcp-server-semgrep has a fix in v1.0.1, but who's checking their MCP server versions? Nobody. That's the problem. https://nvd.nist.gov/vuln/detail/CVE-2026-7446

    Post summary

    The tweet discloses CVE‑2026‑7446 and CVE‑2026‑7416, detailing command injection vulnerabilities that allow unauthenticated OS command execution, and notes a patch for mcp-server-semgrep.

    10001119
    963 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-7416 Remote Command Injection in PolarVista xcode-mcp-server 1.0.0 MCP Interface https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7416

    Post summary

    The entry lists CVE‑2026‑7416 as a Remote Command Injection in PolarVista xcode‑mcp‑server 1.0.0, but provides no PoC, exploit code, or patch information.

    0000033
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-7416 A vulnerability was found in PolarVista xcode-mcp-server 1.0.0. This issue affects the function build_project/run_tests of the file src/index.ts of the component MCP In… https://www.cve.org/CVERecord?id=CVE-2026-7416 ----- Traducción: CVE-2026-7416 Se … http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-7416 in PolarVista xcode-mcp-server 1.0.0, naming the vulnerable function and linking to the official CVE record, but does not provide a PoC, exploit code, patch, or evidence of active exploitation.

    0000030
    74 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-7416 A vulnerability was found in PolarVista xcode-mcp-server 1.0.0. This issue affects the function build_project/run_tests of the file src/index.ts of the component MCP In… https://www.cve.org/CVERecord?id=CVE-2026-7416

    Post summary

    The notice reports a vulnerability in PolarVista xcode-mcp-server with minimal details and no evidence of exploitation or remediation.

    00000199
    57.3K followersView on X

Explore more