Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

CVE-2026-30625: Remote code execution in Upsonic MCP task creation

Upsonic 0.71.6 contains a remote code execution flaw in its MCP server/task creation feature, where an allowlist still permits commands (npm, npx) whose argument flags can run arbitrary OS commands. Maliciously crafted MCP tasks can execute code with the privileges of the Upsonic process.

Disclosed 15 April 2026 · Record updated 13 September 2026

Impact

Maliciously crafted MCP tasks may lead to remote code execution with the privileges of the Upsonic process; version 0.72.0 added a warning that Stdio servers can execute commands directly on the machine.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-30625