Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

CVE-2026-23523: Dive MCP host deeplink allows arbitrary command execution

In the open-source Dive MCP Host Desktop Application prior to version 0.13.0, a crafted deeplink could install an attacker-controlled MCP server configuration without sufficient user confirmation, leading to arbitrary local command execution on the victim's machine. The issue is fixed in version 0.13.0.

Disclosed 16 January 2026 · Record updated 13 September 2026

Impact

Allows an attacker to install a malicious MCP server configuration via deeplink and execute arbitrary commands locally on an affected user's machine.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-23523