CVE-2026-30616

Severity CVSS v4.0:
Pending analysis
Type:
CWE-77 Command Injection
Publication date:
15/04/2026
Last modified:
15/04/2026

Description

Jaaz 1.0.30 contains a remote code execution vulnerability in its MCP STDIO command execution handling. A remote attacker can send crafted network requests to the network-accessible Jaaz application, causing attacker-controlled commands to be executed on the server. Successful exploitation results in arbitrary command execution within the context of the Jaaz service, potentially allowing full compromise of the affected system.