PatchSiren

egtai CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM egtai CVE published 2026-04-28

CVE-2026-7215

CVE-2026-7215 is a command injection vulnerability in egtai gmx-vmd-mcp up to 0.1.0. The issue affects the function launch_vmd_gui_tool of the file mcp_server.py of the component VMD Launch Handler. The manipulation of the argument structure_file/trajectory_file results in command injection. The attack may be launched remotely. This vulnerability has a CVSS score of 5.5 and is considered Medium severity. [truncated]