MEDIUM
idachev
CVE published 2026-04-08
CVE-2026-5802
A vulnerability was identified in idachev mcp-javadc up to 1.2.4, impacting an unknown function of the component HTTP Interface. Manipulation of the argument jarFilePath leads to os command injection, allowing remote attacks. The exploit is publicly available and might be used. The project was informed early but has not responded. Users of idachev mcp-javadc up to 1.2.4 should be aware and take precautions.