functype-mcp-server RCE via unsanitized pnpm install
The set_functype_version MCP tool in functype-mcp-server accepts an unconstrained version string, allowing attackers to inject arbitrary package aliases and execute remote code through dynamic import of attacker-controlled packages.
Disclosed 9 September 2026 · Record updated 13 September 2026
Impact
Remote code execution with full server process privileges (confidentiality, integrity, and availability impact), CVSS 7.8 High
Our coverage
No articles linked to this incident yet.
Sources
- github.comhttps://github.com/advisories/GHSA-wcjj-9m6g-2fr2
