CVE-2026-23523: Dive MCP host deeplink allows arbitrary command execution
In the open-source Dive MCP Host Desktop Application prior to version 0.13.0, a crafted deeplink could install an attacker-controlled MCP server configuration without sufficient user confirmation, leading to arbitrary local command execution on the victim's machine. The issue is fixed in version 0.13.0.
Disclosed 16 January 2026 · Record updated 13 September 2026
Impact
Allows an attacker to install a malicious MCP server configuration via deeplink and execute arbitrary commands locally on an affected user's machine.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-23523
