A vulnerability was identified in bazinga012 mcp_code_executor up to 0.3.0. Affected by this issue is the function installDependencies of the file src/index.ts. Such manipulation leads to command injection.
The attack can only be performed from a local environment. The exploit is publicly available and might be used. It is best practice to apply a patch to resolve this issue.
The project was informed of the problem early through an issue report but has not responded yet.
Attack Parameters
Impact Assessment
CVSS Vector v4.0