Уязвимость была обнаружена в Jij-Inc Jij-MCP-Server 0.1.0. Это влияет на функцию PythonREPL.run файла jij_mcp/python_repr.py компонента jm_check. Манипулирование кодом аргумента приводит к внедрению кода.
Атаку можно запустить удаленно. Эксплойт был обнародован и может быть использован. Проект был заранее проинформирован о проблеме в отчете о проблеме, но пока не ответил.
Показать оригинальное описание (EN)
A vulnerability was found in Jij-Inc Jij-MCP-Server 0.1.0. This affects the function PythonREPL.run of the file jij_mcp/python_repr.py of the component jm_check. The manipulation of the argument code results in code injection. It is possible to launch the attack remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.
Характеристики атаки
Последствия
Строка CVSS v4.0