CVE-2026-30625: Remote code execution in Upsonic MCP task creation
Upsonic 0.71.6 contains a remote code execution flaw in its MCP server/task creation feature, where an allowlist still permits commands (npm, npx) whose argument flags can run arbitrary OS commands. Maliciously crafted MCP tasks can execute code with the privileges of the Upsonic process.
Disclosed 15 April 2026 · Record updated 13 September 2026
Impact
Maliciously crafted MCP tasks may lead to remote code execution with the privileges of the Upsonic process; version 0.72.0 added a warning that Stdio servers can execute commands directly on the machine.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-30625
