PatchSiren

0-Gaurav-0 CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW 0-Gaurav-0 CVE published 2026-09-20

CVE-2026-94031

A vulnerability was detected in 0-Gaurav-0 nexus-mcp aed0026e7ac1f23dc940e46e9fd3a2da6904f914. The issue affects the function child_process.exec of the file src/auth/browser.ts of the component nexus_reauth MCP tool, allowing for command injection via the url argument. This can be exploited remotely. The exploit is now public. The product uses a rolling release system, so version information for affected [truncated]