LOW
Braffolk
CVE published 2026-04-06
CVE-2026-5619
A command injection vulnerability was found in Braffolk mcp-summarization-functions up to 0.1.5. The vulnerability is located in the summarize_command of src/server/mcp-server.ts. An attacker with local access can manipulate the command argument to execute OS commands. This vulnerability requires local access and can be used to execute OS commands, potentially leading to unauthorized system modifications [truncated]