Advisory Database
  • Advisories
  • Dependency Scanning
  1. npm
  2. ›
  3. mcp-server-semgrep
  4. ›
  5. CVE-2026-7446

CVE-2026-7446: mcp-server-semgrep has a Command Injection issue

April 30, 2026 (updated May 6, 2026)

A vulnerability was detected in VetCoders mcp-server-semgrep 1.0.0. This affects the function analyze_results/filter_results/export_results/compare_results/scan_directory/create_rule of the file src/index.ts of the component MCP Interface. The manipulation of the argument ID results in os command injection. The attack can be executed remotely. The exploit is now public and may be used. Upgrading to version 1.0.1 is able to mitigate this issue. The patch is identified as 141335da044e53c3f5b315e0386e01238405b771. It is advisable to upgrade the affected component.

References

  • github.com/VetCoders/mcp-server-semgrep
  • github.com/VetCoders/mcp-server-semgrep/commit/141335da044e53c3f5b315e0386e01238405b771
  • github.com/VetCoders/mcp-server-semgrep/issues/12
  • github.com/VetCoders/mcp-server-semgrep/pull/15
  • github.com/VetCoders/mcp-server-semgrep/releases/tag/v1.0.1
  • github.com/advisories/GHSA-86hp-qxqp-w9wv
  • nvd.nist.gov/vuln/detail/CVE-2026-7446
  • vuldb.com/submit/804100
  • vuldb.com/vuln/360187
  • vuldb.com/vuln/360187/cti

Code Behaviors & Features

Detect and mitigate CVE-2026-7446 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 1.0.1

Fixed versions

  • 1.0.1

Solution

Upgrade to version 1.0.1 or above.

Impact 7.3 HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Learn more about CVSS

Weakness

  • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')

Source file

npm/mcp-server-semgrep/CVE-2026-7446.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sat, 09 May 2026 12:17:52 +0000.