PatchSiren

idachev CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM idachev CVE published 2026-04-08

CVE-2026-5802

A vulnerability was identified in idachev mcp-javadc up to 1.2.4, impacting an unknown function of the component HTTP Interface. Manipulation of the argument jarFilePath leads to os command injection, allowing remote attacks. The exploit is publicly available and might be used. The project was informed early but has not responded. Users of idachev mcp-javadc up to 1.2.4 should be aware and take precautions.