Impact
The vulnerability resides in the executeMagerun2Command function within the elgentos magento2-dev-mcp package, allowing local attackers to inject arbitrary operating‑system commands. This flaw permits execution of commands on the system where the component runs, potentially compromising confidentiality, integrity, and availability of that environment. The weakness is categorized as OS Command Injection (CWE-77, CWE-78).
Affected Systems
The affected product is elgentos magento2-dev-mcp, with all releases up to and including version 1.0.2 vulnerable. No other vendors or products are listed as impacted.
Risk and Exploitability
The CVSS base score is 4.8, which places the vulnerability in the Low severity range. The EPSS score is not available, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation requires local access, as stated by the vendor, and a public exploit is available. While remote exploitation is not feasible, the presence of a local command‑injection vector remains a concern for systems that allow local users to invoke the component.
OpenCVE Enrichment
Github GHSA