Description
A vulnerability was identified in XixianLiang HarmonyOS-mcp-server 0.1.0. This vulnerability affects the function input_text. The manipulation of the argument text leads to os command injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
Problem types
Product status
Timeline
| 2026-02-06: | Advisory disclosed |
| 2026-02-06: | VulDB entry created |
| 2026-02-09: | VulDB entry last update |
Credits
Lexpl0it (VulDB User)
References
vuldb.com/?id.344766 (VDB-344766 | XixianLiang HarmonyOS-mcp-server input_text os command injection)
vuldb.com/?ctiid.344766 (VDB-344766 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.747209 (Submit #747209 | GitHub HarmonyOS-mcp-server v0.1.0 Command Injection)
github.com/...main/HarmonyOS-mcp-server RCE vulnerability.md