Impact
A local vulnerability exists in the server.tool function of index.js within the Tshark CLI Command Handler of 0xKoda WireMCP. The flaw allows an attacker with local access to manipulate input and trigger arbitrary OS command execution, exposing the system to integrity compromise. This is a classic OS command injection attack (CWE‑77/CWE‑78).
Affected Systems
Affected systems include deployments of 0xKoda WireMCP up to commit 7f45f8b2b4adeb76be8c6227eefb38533fdd6b1e. Because the project uses a rolling release model, exact released version numbers are not publicly disclosed, but any instance running code before the unreported fix is vulnerable.
Risk and Exploitability
The CVSS score of 4.8 indicates moderate severity, and the EPSS score of less than 1% signals a low likelihood of widespread exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog and requires local access; thus the risk to remote users is limited. However, local attackers could gain unauthenticated command execution if the affected component is reachable.
OpenCVE Enrichment