Ad

CVE-2026-25905

MEDIUM CVSS 3.1: 5.8 EPSS 0.01%
Updated Feb 09, 2026
Python
Parameter Value
CVSS 5.8 (MEDIUM)
Type CWE-653
Vendor Python
Public PoC No

The Python code being run by 'runPython' or 'runPythonAsync' is not isolated from the rest of the JS code, allowing any Python code to use the Pyodide APIs to modify the JS environment. This may result in an attacker hijacking the MCP server - for malicious purposes including MCP tool shadowing. Note - the "mcp-run-python" project is archived and unlikely to receive a fix.

Attack Parameters

Attack Vector
Network
Атака возможна удалённо
Attack Complexity
High
Сложно эксплуатировать
Privileges Required
None
Права не нужны
User Interaction
Required
Нужно действие пользователя

Impact Assessment

Confidentiality
Low
Частичная утечка данных
Integrity
Low
Частичная модификация данных
Availability
Low
Частичное нарушение работы

CVSS Vector v3.1

Weakness Type (CWE)