CVE-2026-7642Active Exploitation

LOWCVSS 2.1 · LOW

Exploitation ongoing with high activity in latest observed window (3 mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

A vulnerability was detected in pskill9 website-downloader up to 0.1.0. This affects the function download_website of the file src/index.ts of the component MCP Interface. Performing a manipulation of the argument outputPath results in os command injection. The attack may be initiated remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • Active exploitation appears in 1 classified signals
  • 3 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-05-02: 3Active Exploitation · 2026-05-02: 1Technical Details · 2026-05-02: 305-02
Signal classification3 categories
Active Exploitation
133.3%
Disclosure
133.3%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-7642 A vulnerability was detected in pskill9 website-downloader up to 0.1.0. This affects the function download_website of the file src/index.ts of the component MCP Interfa… https://www.cve.org/CVERecord?id=CVE-2026-7642

    Post summary

    CVE-2026-7642 was identified in the pskill9 website‑downloader v0.1.0, specifically impacting the download_website function in src/index.ts. No exploit, patch, or active exploitation details are provided.

    00010285
    57.4K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Active Exploitation

    CVE-2026-7642 OS Command Injection in pskill9 website-downloader Up to 0.1.0 (Exploitation Reported) https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7642

    Post summary

    CVE‑2026‑7642 is an OS Command Injection flaw in pskill9 website‑downloader (up to 0.1.0) that has been reported as actively exploited in the wild.

    0000073
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-7642 A vulnerability was detected in pskill9 website-downloader up to 0.1.0. This affects the function download_website of the file src/index.ts of the component MCP Interfa… https://www.cve.org/CVERecord?id=CVE-2026-7642 ----- Traducción: CVE-2026-7642 Se … http://infoflow.cloud`

    Post summary

    The tweet simply references CVE‑2026‑7642, noting the affected function and linking to the CVE record, but provides no PoC, exploit code, or evidence of active exploitation.

    0000045
    75 followersView on X

Explore more