CVE-2026-58195: Agentic-Flow Command Injection via MCP Server Tools
Agentic-Flow prior to version 2.0.14 contains a command injection vulnerability in MCP server tools where attacker-controlled parameters are directly interpolated into shell commands passed to execSync(), allowing arbitrary OS command execution with server privileges.
Disclosed 17 July 2026 · Record updated 13 September 2026
Impact
Arbitrary OS command execution with the privileges of the MCP server user through unsanitized parameter interpolation in shell commands.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-58195
