@elgentos/magento2-dev-mcp vulnerable to command injection
Low severity
GitHub Reviewed
Published
Apr 6, 2026
to the GitHub Advisory Database
•
Updated Apr 6, 2026
Description
Published by the National Vulnerability Database
Apr 5, 2026
Published to the GitHub Advisory Database
Apr 6, 2026
Reviewed
Apr 6, 2026
Last updated
Apr 6, 2026
A vulnerability was identified in elgentos magento2-dev-mcp up to 1.0.2. The affected element is the function executeMagerun2Command of the file src/index.ts. Such manipulation leads to os command injection. An attack has to be approached locally. The exploit is publicly available and might be used. The name of the patch is aa1ffcc0aea1b212c69787391783af27df15ae9d. A patch should be applied to remediate this issue.
References