No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 06 Aug 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 06 Aug 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was detected in Kino-Kafkaesque ssh-mcp-server up to 8ebbbb99b26f80ff6162fe00957c6dec73fbc5a5. Impacted is the function ssh_exec of the file src/index.ts of the component SSH Command Handler. Performing a manipulation of the argument host/username results in command injection. The attack requires a local approach. The actual existence of this vulnerability is currently in question. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The project maintainer explains: "The intended threat model is that this MCP server is a local/trusted tool for an agent to execute commands over SSH, so callers already have meaningful execution capability through the exposed shell." | |
| Title | Kino-Kafkaesque ssh-mcp-server SSH index.ts ssh_exec command injection | |
| First Time appeared |
Kino-kafkaesque
Kino-kafkaesque ssh-mcp-server |
|
| Weaknesses | CWE-74 CWE-77 |
|
| CPEs | cpe:2.3:a:kino-kafkaesque:ssh-mcp-server:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Kino-kafkaesque
Kino-kafkaesque ssh-mcp-server |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-08-06T13:59:05.205Z
Reserved: 2026-08-06T05:56:33.587Z
Link: CVE-2026-19039
Updated: 2026-08-06T13:57:40.410Z
No data.
No data.
OpenCVE Enrichment
No data.