Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Command injection in awwaiid mcp-server-taskwarrior up to 1.0.1 (CVE-2026-5833)

A command injection vulnerability was disclosed in the MCP server mcp-server-taskwarrior up to version 1.0.1, where manipulation of the Identifier argument in the server.setRequestHandler function of index.ts allows local command injection. The exploit was publicly disclosed and the maintainer released a patched version.

Disclosed 9 April 2026 · Record updated 13 September 2026

Impact

Local attackers could inject and execute arbitrary commands via the Identifier argument handled by the MCP server; a patch (commit 1ee3d282debfa0a99afeb41d22c4b2fd5a3148f2) was released.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-5833