CVE-2025-10619 Details
Description
A vulnerability was detected in sequa-ai sequa-mcp up to 1.0.13. This affects the function redirectToAuthorization of the file src/helpers/node-oauth-client-provider.ts of the component OAuth Server Discovery. Performing manipulation results in os command injection. Remote exploitation of the attack is possible. The exploit is now public and may be used. Upgrading to version 1.0.14 is able to mitigate this issue. The patch is named e569815854166db5f71c2e722408f8957fb9e804. It is recommended to upgrade the affected component. The vendor explains: "We only promote that mcp server with our own URLs that have a valid response, but yes if someone would use it with a non sequa url, this is a valid attack vector. We have released a new version (1.0.14) that fixes this and validates that only URLs can be opened."
A critical OS command injection vulnerability has been identified in Sequa-AI Sequa-MCP versions through 1.0.13. The issue arises in the OAuth Server Discovery component, specifically within the 'redirectToAuthorization' function of 'src/helpers/node-oauth-client-provider.ts'. The vulnerability allows remote exploitation by injecting commands that are executed on the host machine.
Upgrade to Sequa-MCP version 1.0.14, which includes a patch that validates authorization URLs before they are opened. The patched version is available on the project's GitHub repository.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 17, 2025CISA-ADP
Assessed Sep 18, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://lavender-bicycle-a5a.notion.site/Sequa-MCP-RCE-26853a41781f807da1c0cd158f9e3e1a | CISA-ADP | |
| https://github.com/sequa-ai/sequa-mcp/commit/e569815854166db5f71c2e722408f8957fb9e804 | [email protected] | Source CodeVendor |
| https://lavender-bicycle-a5a.notion.site/Sequa-MCP-RCE-26853a41781f807da1c0cd158f9e3e1a?source=copy_link | [email protected] | ExploitPartial Content |
| https://vuldb.com/?ctiid.324646 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/?id.324646 | [email protected] | AdvisoryExploitRemedy |
| https://vuldb.com/?submit.650189 | [email protected] | ExploitTechnical Description |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-77 | Improper Neutralization of Special Elements used in a Command ('Command Injection') | [email protected] |
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| sequa-ai sequa-mcp | All versions |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 26, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Data Remediation | [email protected] |
| Sep 18, 2025 | CVE Modified | CISA-ADP |
| Sep 17, 2025 | New CVE Received | [email protected] |
Volerion