Vulnerability  ·  2026-10-01

pi-llm-wiki wiki_capture_source MCP tool OS command injection (remote)

VulnerabilityHigh impactGlobalCVE-2026-102911
NVD published with CVSS 9.9 and notes an exploit has been published. The MCP tool's url argument flows into OS-level command execution without validation, giving remote code execution in an agent-connected tool server.
MCP tool servers extend agent trust to the host; a remote command injection in a capture/ingestion tool means anyone who can talk to the MCP server (often an exposed, unauthenticated service) reaches the host OS — the same class as the recent mcp-atlassian chain.
An attacker passes a crafted url argument to the wiki_capture_source MCP tool; the value is mishandled such that os command injection executes attacker commands on the MCP server host.
zosmaai pi-llm-wiki up to and including 0.11.7 (mcp/index.ts, wiki_capture_source MCP tool)
Upgrade pi-llm-wiki beyond 0.11.7; restrict access to the MCP tool endpoint until patched.
NVDTenable CVE recordpi-llm-wiki repository
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →