В MIMICLab mcp-pdf-vision 1.1.0 обнаружена уязвимость. Затронутым элементом является функция load_pdf файла src/index.ts. Такая манипуляция аргументом pdfPath/sessionId приводит к внедрению команды.
Атака может быть выполнена только из локальной среды. Проект был заранее проинформирован о проблеме в отчете о проблеме, но пока не ответил.
Показать оригинальное описание (EN)
A vulnerability was identified in MIMICLab mcp-pdf-vision 1.1.0. The impacted element is the function load_pdf of the file src/index.ts. Such manipulation of the argument pdfPath/sessionId leads to command injection. The attack can only be performed from a local environment. The project was informed of the problem early through an issue report but has not responded yet.
Характеристики атаки
Последствия
Строка CVSS v4.0