CVE-2026-30635 | automagik-genie 2.5.27 MCP Server dist/mcp/server.js readTranscriptFromCommit command injection
A vulnerability labeled as critical has been found in automagik-genie 2.5.27. This affects the function readTranscriptFromCommit of the file dist/mcp/server.js of the component MCP Server. The manipulation results in command injection.
This vulnerability is cataloged as CVE-2026-30635. The attack must originate from the local network. There is no exploit available.