MEDIUM
AgentDeskAI
CVE published 2026-04-26
CVE-2026-7064
A flaw in AgentDeskAI browser-tools-mcp up to 1.2.0 can lead to os command injection via manipulation of the browser-tools-server/browser-connector.ts file. The attack may be performed remotely. Upgrading to version 2.0.0 addresses this issue. Defenders should assess exposure and prioritize upgrading to version 2.0.0. The vulnerability affects the browser-tools-server/browser-connector.ts file, allowing f [truncated]