CVE-2026-5528 | MoussaabBadla code-screenshot-mcp up to 0.1.0 HTTP Interface os command injection
A vulnerability, which was classified as critical, was found in MoussaabBadla code-screenshot-mcp up to 0.1.0. This affects an unknown part of the component HTTP Interface. Such manipulation leads to os command injection.
This vulnerability is referenced as CVE-2026-5528. It is possible to launch the attack remotely. Furthermore, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.