CVE-2026-7628Disclosure

LOWCVSS 2.1 · LOW

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was detected in crazyrabbitLTC mcp-code-review-server up to 0.1.0. This issue affects the function executeRepomix of the file src/repomix.ts of the component RepoMix Command Handler. Performing a manipulation results in command injection. The attack may be initiated remotely. The exploit is now public and may be used. The project was informed of the problem early through a pull request but has not reacted yet.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-77

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 4 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 4 classified signals
  • 4 total mentions across 1 day

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-05-02: 4Technical Details · 2026-05-02: 305-02
Signal classification1 categories
Disclosure
4100.0%
Referenced assets4 URLs
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-7628 A vulnerability was detected in crazyrabbitLTC mcp-code-review-server up to 0.1.0. This issue affects the function executeRepomix of the file src/repomix.ts of the comp… https://www.cve.org/CVERecord?id=CVE-2026-7628

    Post summary

    A new vulnerability (CVE-2026-7628) was identified in the crazyrabbitLTC mcp-code-review-server up to version 0.1.0, affecting the executeRepomix function in src/repomix.ts. No PoC, exploit, or patch information is provided.

    00010297
    57.4K followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    @CVEnew CVE-2026-7628 highlights a critical flaw in crazyrabbitLTC—exploiting executeRepomix could lead to unauthorized actions. Always monitor your code dependencies. http://research.lyrie.ai/streams/cve-2026-7628

    Post summary

    The tweet announces the discovery of CVE-2026-7628, highlighting a critical flaw in crazyrabbitLTC that could enable unauthorized actions, without providing a proof‑of‑concept, exploit code, or patch details.

    0000036
    152 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-7628 Command Injection in crazyrabbitLTC mcp-code-review-server 0.1.0 RepoMix Handler https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7628

    Post summary

    The text announces CVE-2026-7628 as a command injection flaw affecting the RepoMix Handler of crazyrabbitLTC mcp-code-review-server 0.1.0, with a reference to further details on vulmon.com.

    0000061
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-7628 A vulnerability was detected in crazyrabbitLTC mcp-code-review-server up to 0.1.0. This issue affects the function executeRepomix of the file src/repomix.ts of the comp… https://www.cve.org/CVERecord?id=CVE-2026-7628 ----- Traducción: CVE-2026-7628 Se … http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-7628, affecting the executeRepomix function in crazyrabbitLTC mcp-code-review-server up to 0.1.0, but offers only minimal technical detail and no PoC, exploit, or patch information.

    0000029
    75 followersView on X

Explore more