CVE-2026-16488 Details
Description
A vulnerability was determined in QUSETIONS MiniCode-Python 0.1.0. This vulnerability affects the function subprocess.Popen of the file minicode/config.py of the component Project File Handler. Executing a manipulation can lead to os command injection. The attack may be launched remotely. A high complexity level is associated with this attack. It is stated that the exploitability is difficult. The exploit has been publicly disclosed and may be utilized. Upgrading to version 0.1.0-rc1 is able to resolve this issue. This patch is called 9d868dc2550f426c6ddf8ee98f30ffe450ca5e32. It is suggested to upgrade the affected component.
An OS command injection vulnerability has been identified in QUSETIONS MiniCode-Python version 0.1.0. The issue arises in the Project File Handler component, specifically within the subprocess.Popen function in minicode/config.py. This vulnerability allows for remote command execution on the operating system. The exploitation complexity is high, making it a challenging vulnerability to exploit. However, the vulnerability has been publicly disclosed and could be used in attacks.
Upgrade to QUSETIONS MiniCode-Python version 0.1.0-rc1, which requires explicit opt-in to load project-level .mcp.json files. Instructions for downloading this version are available on the MiniCode-Python GitHub releases page.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 22, 2026CISA-ADP
Assessed Jul 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gist.github.com/menelausx/2e6275222cb2e8aa412a145ba7abec66 | [email protected] | ExploitTechnical Analysis |
| https://github.com/QUSETIONS/MiniCode-Python/ | [email protected] | Source CodeVendor |
| https://github.com/QUSETIONS/MiniCode-Python/commit/9d868dc2550f426c6ddf8ee98f30ffe450ca5e32 | [email protected] | Source CodeVendor |
| https://github.com/QUSETIONS/MiniCode-Python/issues/13 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/QUSETIONS/MiniCode-Python/issues/13#issuecomment-4764889606 | [email protected] | Issue TrackingTechnical DescriptionVendor |
| https://github.com/QUSETIONS/MiniCode-Python/releases/tag/v0.1.0-rc1 | [email protected] | Release NotesVendor |
| https://vuldb.com/cve/CVE-2026-16488 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/860017 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/380945 | [email protected] | BundlePermission Required |
| https://vuldb.com/vuln/380945/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-77 | Improper Neutralization of Special Elements used in a Command ('Command Injection') | [email protected] |
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| QUSETIONS MiniCode-Python | 0.1.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 22, 2026 | CVE Modified | CISA-ADP |
| Jul 22, 2026 | New CVE Received | [email protected] |
Volerion