Description
A flaw has been found in ArtMin96 yii2-mcp-server 1.0.2. This impacts the function yii_command_help/yii_execute_command of the file src/index.ts of the component MCP Interface. Executing a manipulation can lead to os command injection. The attack can be executed remotely. The exploit has been published and may be used.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 1.0.2
References
Related Issues
- WebdriverIO BrowserStack Service has a Command Injection issue - CVE-2026-25244
- @yoda.digital/gitlab-mcp-server's SSE transport has no authentication and wildcard CORS, exposing all 86 GitLab tools - CVE-2026-44895
- Parse Server has a SQL injection via query field name when using PostgreSQL - CVE-2026-32234
- React Router has CSRF issue in Action/Server Action Request Processing - CVE-2026-22030
You might also like:
- Tags:
- npm
- yii2-mcp-server
Anything's wrong? Let us know Last updated on May 07, 2026


