Description
A vulnerability has been found in jackwrichards FastlyMCP up to 6f3d0b0e654fc51076badc7fa16c03c461f95620. This impacts an unknown function of the file fastly-mcp.mjs of the component fastly_cli Tool. The manipulation of the argument command leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-04-28
Score: 6.9 Medium
EPSS: 2.1% Low
KEV: No
Impact: Remote code execution through OS command injection
Action: Monitor
AI Analysis

Impact

The vulnerability lies in an unvalidated command argument in fastly-mcp.mjs of the fastly_cli tool, allowing an attacker to inject arbitrary operating system commands. This classic OS command injection can lead to full compromise of the host executing the tool, giving remote execution of any command and potentially granting full system control. The weakness is categorized under CWE‑77 and CWE‑78, indicating improper command argument handling and unsanitized shell execution.

Affected Systems

All releases of jackwrichards' FastlyMCP up to the commit 6f3d0b0e654fc51076badc7fa16c03c461f95620 are vulnerable. The project employs a rolling release model, so affected versions span the current codebase until an update is published. The tool in question (fastly_cli) is the impacted component, and no earlier versions are known to be unaffected.

Risk and Exploitability

The CVSS score of 6.9 places the issue in a moderate severity bucket, and the EPSS score of 1%. The vulnerability is not listed in CISA's KEV catalog, indicating no known widely‑publicized exploits. However, the description states the attack can be initiated remotely, implying that an adversary could potentially exploit the injection from a network or remote session if the tool is exposed. Given the lack of patch and public disclosure, the risk remains real for any system running the vulnerable tool.

Generated by OpenCVE AI on April 28, 2026 at 19:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Disable or remove the fastly_cli tool until an official fix is released
  • Restrict execution of the tool to the least privileged user and ensure it cannot spawn arbitrary shell commands
  • Monitor the vendor’s repository or release channel for an update and apply the patch as soon as it becomes available

Generated by OpenCVE AI on April 28, 2026 at 19:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Apr 2026 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 28 Apr 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Jackwrichards
Jackwrichards fastlymcp
Vendors & Products Jackwrichards
Jackwrichards fastlymcp

Tue, 28 Apr 2026 04:15:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in jackwrichards FastlyMCP up to 6f3d0b0e654fc51076badc7fa16c03c461f95620. This impacts an unknown function of the file fastly-mcp.mjs of the component fastly_cli Tool. The manipulation of the argument command leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.
Title jackwrichards FastlyMCP fastly_cli Tool fastly-mcp.mjs os command injection
Weaknesses CWE-77
CWE-78
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Jackwrichards Fastlymcp
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-04-28T12:38:36.720Z

Reserved: 2026-04-27T15:32:47.599Z

Link: CVE-2026-7220

cve-icon Vulnrichment

Updated: 2026-04-28T12:38:32.269Z

cve-icon NVD

Status : Deferred

Published: 2026-04-28T04:16:26.017

Modified: 2026-04-29T01:00:01.613

Link: CVE-2026-7220

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T19:45:07Z

Weaknesses