CVE-2026-19047

Severity CVSS v4.0:
LOW
Type:
CWE-74 Injection
Publication date:
06/08/2026
Last modified:
12/08/2026

Description

A vulnerability was detected in NocteDefensor LudusMCP up to 1.0.24. This affects the function executeArbitraryCommand/executeCommand of the file src/ludusMCP/cliWrapper.ts of the component ludus_cli_execute. Performing a manipulation of the argument command/args results in command injection. The attack needs to be approached locally. The project was informed of the problem early through an issue report but has not responded yet.