CVE-2026-7593Disclosure

LOWCVSS 5.5 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A security vulnerability has been detected in Sunwood-ai-labs command-executor-mcp-server up to 0.1.0. This impacts the function execute_command of the file src/index.ts of the component MCP Interface. The manipulation leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 2 mentions (2026-05-01); latest day: 2
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-05-01: 2Mentions · 2026-05-02: 2Technical Details · 2026-05-01: 2Technical Details · 2026-05-02: 205-0105-02
Signal classification1 categories
Disclosure
4100.0%
Referenced assets3 URLs
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-7593 A security vulnerability has been detected in Sunwood-ai-labs command-executor-mcp-server up to 0.1.0. This impacts the function execute_command of the file src/index.t… https://www.cve.org/CVERecord?id=CVE-2026-7593

    Post summary

    This brief notice discloses CVE-2026-7593 as a vulnerability in Sunwood-ai-labs command-executor-mcp-server up to version 0.1.0, affecting the execute_command function. No PoC, exploit, patch, or active exploitation details are given.

    01010262
    57.7K followersView on X
  • Abcas MCP Guard@abcas_mcp_guard
    Disclosure

    Local MCP servers are the next productivity frontier, but they are also a new attack surface. CVE-2026-7593 (Sunwood-ai-labs) shows that RCE is a real threat in the MCP ecosystem. 🛡️ Always audit your tools. #MCPSecurity #MCP #CyberSecurity

    Post summary

    The post announces CVE‑2026‑7593 affecting MCP servers, noting it enables remote code execution, but offers no additional technical detail, exploit code, or remediation steps.

    0000053
    13 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-7593 Remote Code Execution via OS Command Injection in Sunwood-ai-labs Command-Executor-MCP-Server 0.1.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7593

    Post summary

    The text announces CVE‑2026‑7593, detailing a RCE vulnerability from OS command injection in Sunwood‑ai‑labs Command‑Executor‑MCP‑Server, but offers no proof of concept, exploit tools, or mitigation information.

    0000066
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-7593 A security vulnerability has been detected in Sunwood-ai-labs command-executor-mcp-server up to 0.1.0. This impacts the function execute_command of the file src/index.t… https://www.cve.org/CVERecord?id=CVE-2026-7593 ----- Traducción: CVE-2026-7593 Se … http://infoflow.cloud`

    Post summary

    A new CVE (2026‑7593) has been announced, detailing the affected component and function, but no exploit, PoC, or patch information is provided.

    0000058
    75 followersView on X

Explore more