Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

CVE-2026-22792: 5ire MCP client HTML injection enables MCP server creation and RCE

Versions of the 5ire cross-platform desktop AI assistant and Model Context Protocol client prior to 0.15.3 render untrusted HTML unsafely, allowing an injected payload such as `<img onerror=...>` to execute arbitrary JavaScript in the renderer. The script can call exposed bridge APIs like window.bridge.mcpServersManager.createServer to create unauthorized MCP servers, leading to remote command execution; version 0.15.3 fixes the issue.

Disclosed 21 January 2026 · Record updated 13 September 2026

Impact

Arbitrary JavaScript execution in the renderer could create unauthorized MCP servers and lead to remote command execution on affected desktop installations.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-22792