White Rabbitx 🏴☠️[verified]@TheRabbitPyDisclosure
A new OS command injection vulnerability (CVE‑2026‑7446) in VetCoders mcp‑server‑semgrep v1.0.0 has been disclosed, describing the improper handling of an ID argument.
Vito Botta[verified]@vitobottaPatch
The post identifies two command injection vulnerabilities in MCP servers, notes a published patch for one, and criticizes the lack of version checks, without indicating active exploitation or PoC details.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
A remote OS command injection vulnerability has been identified in VetCoders mcp-server-semgrep 1.0.0. No PoC, exploit code, active exploitation, or patch information was provided.
Infoflowcloud@infoflowcloudGeneral
The post announces CVE-2026-7446 as affecting certain VetCoders functions but gives no additional technical, exploit, or mitigation details.
CVE@CVEnewDisclosure
A new CVE-2026-7446 vulnerability was reported for VetCoders mcp-server-semgrep 1.0.0 affecting several functions, but no PoC, exploit, active exploitation, patch, or technical details are provided.