What happened
NVD published with CVSS 9.9 and notes an exploit has been published. The MCP tool's url argument flows into OS-level command execution without validation, giving remote code execution in an agent-connected tool server.
Why it matters
MCP tool servers extend agent trust to the host; a remote command injection in a capture/ingestion tool means anyone who can talk to the MCP server (often an exposed, unauthenticated service) reaches the host OS — the same class as the recent mcp-atlassian chain.
Attack vector
An attacker passes a crafted url argument to the wiki_capture_source MCP tool; the value is mishandled such that os command injection executes attacker commands on the MCP server host.
Affected systems
zosmaai pi-llm-wiki up to and including 0.11.7 (mcp/index.ts, wiki_capture_source MCP tool)
Mitigation
Upgrade pi-llm-wiki beyond 0.11.7; restrict access to the MCP tool endpoint until patched.