Command injection in awwaiid mcp-server-taskwarrior up to 1.0.1 (CVE-2026-5833)
A command injection vulnerability was disclosed in the MCP server mcp-server-taskwarrior up to version 1.0.1, where manipulation of the Identifier argument in the server.setRequestHandler function of index.ts allows local command injection. The exploit was publicly disclosed and the maintainer released a patched version.
Disclosed 9 April 2026 · Record updated 13 September 2026
Impact
Local attackers could inject and execute arbitrary commands via the Identifier argument handled by the MCP server; a patch (commit 1ee3d282debfa0a99afeb41d22c4b2fd5a3148f2) was released.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-5833
