CVE-2026-7653General

LOWCVSS 2.1 · LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A security flaw has been discovered in r-huijts mcp-server-rijksmuseum up to 1.0.4. Affected is the function open_image_in_browser of the file src/index.ts of the component MCP Interface. Performing a manipulation of the argument imageUrl results in os command injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • General: 3 classified signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-05-02); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-05-02: 3Mentions · 2026-05-03: 1Technical Details · 2026-05-02: 305-0205-03
Signal classification2 categories
General
375.0%
Disclosure
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-023
Disclosure1General2
2026-05-031
General1
Full discourse4 posts
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-7653 A security flaw has been discovered in r-huijts mcp-server-rijksmuseum up to 1.0.4. Affected is the function open_image_in_browser of the file src/index.ts of the compo… https://www.cve.org/CVERecord?id=CVE-2026-7653 ----- Traducción: CVE-2026-7653 Se … http://infoflow.cloud`

    Post summary

    The note flags a vulnerability in r‑huijts mcp‑server‑rijksmuseum’s open_image_in_browser function (src/index.ts) and points to the CVE record, but offers no exploit code, PoC, active exploitation evidence, or patch information.

    0001052
    75 followersView on X
  • Abcas MCP Guard@abcas_mcp_guard
    General

    MCP security is more than just checking permissions. New vulnerabilities like CVE-2026-7653 show that even simple functions can be vectors. Continuous scanning is the only way to stay ahead. Protect your agents with MCP Guard. 🛡️ #MCPSecurity #MCP #CyberSecurity

    Post summary

    The tweet briefly mentions a new CVE (CVE-2026-7653) as an example of vulnerabilities in simple functions, urging continuous scanning and agent protection, but provides no technical details, exploit information, or patch guidance.

    0000039
    13 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-7653 A security flaw has been discovered in r-huijts mcp-server-rijksmuseum up to 1.0.4. Affected is the function open_image_in_browser of the file src/index.ts of the compo… https://www.cve.org/CVERecord?id=CVE-2026-7653

    Post summary

    The text announces the discovery of CVE-2026-7653 affecting the open_image_in_browser function in r-huijts mcp-server-rijksmuseum, providing some technical details but no evidence of exploitation or patch information.

    00000304
    57.4K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-7653 Remote Command Injection in r-huijts mcp-server-rijksmuseum Up To 1.0.4 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7653

    Post summary

    A straightforward disclosure of CVE‑2026‑7653, describing a remote command injection flaw in r‑huijts mcp‑server‑rijksmuseum up to version 1.0.4, with a reference to a vulnerability detail page.

    0000056
    4.0K followersView on X

Explore more