LOW
ChrisChinchilla
CVE published 2026-04-06
CVE-2026-5621
A vulnerability was found in ChrisChinchilla Vale-MCP up to 0.1.0. Affected by this vulnerability is an unknown functionality of the file src/index.ts of the component HTTP Interface. The manipulation of the argument config_path results in os command injection. Attacking locally is a requirement. The vulnerability is caused by improper handling of the config_path argument in the HTTP Interface of ChrisChi [truncated]