Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

CVE-2026-43901: Wireshark MCP server allows arbitrary export path via unsandboxed tool

Wireshark-MCP versions 1.1.5 and earlier expose a wireshark_export_objects MCP tool that passes an attacker-controlled dest_dir parameter to tshark's --export-objects flag without mandatory path restriction. Because the path sandbox is disabled unless WIRESHARK_MCP_ALLOWED_DIRS is set, a default installation permits exporting files to any directory on the filesystem.

Disclosed 11 May 2026 · Record updated 13 September 2026

Impact

An attacker able to invoke the MCP tool can direct tshark to write exported objects to any directory on the host filesystem in a default installation.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-43901