Description
A flaw has been found in kleneway awesome-cursor-mpc-server up to 2.0.1. Impacted is the function runCodeReviewTool of the file src/tools/codeReview.ts of the component Ccode-Review Tool. Executing a manipulation can lead to command injection. The attack may be launched remotely. The exploit has been published and may be used. The project was informed of the problem early through a pull request but has not reacted yet.
Problem types
Product status
2.0.1
Timeline
| 2026-05-01: | Advisory disclosed |
| 2026-05-01: | VulDB entry created |
| 2026-05-01: | VulDB entry last update |
Credits
Yinci Chen (VulDB User)
VulDB CNA Team
References
github.com/kleneway/awesome-cursor-mpc-server/issues/6
vuldb.com/vuln/360575 (VDB-360575 | kleneway awesome-cursor-mpc-server Ccode-Review Tool codeReview.ts runCodeReviewTool command injection)
vuldb.com/vuln/360575/cti (VDB-360575 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/submit/806470 (Submit #806470 | kleneway awesome-cursor-mpc-server <=2.0.1 Command Injection)
github.com/kleneway/awesome-cursor-mpc-server/issues/6
github.com/kleneway/awesome-cursor-mpc-server/pull/14
github.com/...les/26019723/awesome-cursor-mpc-server_bug.pdf
github.com/kleneway/awesome-cursor-mpc-server/