PatchSiren

ChrisChinchilla CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW ChrisChinchilla CVE published 2026-04-06

CVE-2026-5621

A vulnerability was found in ChrisChinchilla Vale-MCP up to 0.1.0. Affected by this vulnerability is an unknown functionality of the file src/index.ts of the component HTTP Interface. The manipulation of the argument config_path results in os command injection. Attacking locally is a requirement. The vulnerability is caused by improper handling of the config_path argument in the HTTP Interface of ChrisChi [truncated]