CVE-2026-30625 Details
Description
Upsonic 0.71.6 contains a remote code execution vulnerability in its MCP server/task creation functionality. The application allows users to define MCP tasks with arbitrary command and args values. Although an allowlist exists, certain allowed commands (npm, npx) accept argument flags that enable execution of arbitrary OS commands. Maliciously crafted MCP tasks may lead to remote code execution with the privileges of the Upsonic process. In version 0.72.0 Upsonic added a warning about using Stdio servers being able to execute commands directly on the machine.
A remote code execution vulnerability has been identified in Upsonic version 0.71.6, specifically within its MCP server task creation feature. The application permits users to create MCP tasks by specifying arbitrary commands and arguments. While there is an allowlist, certain permitted commands, such as npm and npx, can be exploited to execute arbitrary operating system commands. This vulnerability arises because the application executes the injected commands without proper validation or sanitization, leading to remote code execution with the privileges of the Upsonic process.
Users are advised to update to Upsonic version 0.72.0 or later, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 15, 2026CISA-ADP
Assessed Apr 16, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Upsonic/Upsonic/commit/855053fce0662227d9246268ff4a0844b481a305 | [email protected] | Source CodeVendor |
| https://www.ox.security/blog/mcp-supply-chain-advisory-rce-vulnerabilities-across-the-ai-ecosystem/ | [email protected] | BundleRemedyTechnical Analysis |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-77 | Improper Neutralization of Special Elements used in a Command ('Command Injection') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Upsonic | All versions |
CPE
Remediation
| |
| Anthropic MCP | All versions |
CPE
Remediation
| |
| LangFlow | All versions |
CPE
Remediation
| |
| GPT Researcher | All versions |
CPE
Remediation
| |
| LiteLLM | All versions |
CPE
Remediation
| |
| Agent Zero | All versions |
CPE
Remediation
| |
| LangBot | All versions |
CPE
Remediation
| |
| Fay Digital Human Framework | All versions |
CPE
Remediation
| |
| Bisheng | All versions |
CPE
Remediation
| |
| Jaaz | All versions |
CPE
Remediation
| |
| Langchain-Chatchat | All versions |
CPE
Remediation
| |
| Windsurf | All versions |
CPE
Remediation
| |
| DocsGPT | All versions |
CPE
Remediation
| |
| LettaAI | All versions |
CPE
Remediation
| |
| Flowise | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 16, 2026 | CVE Modified | CISA-ADP |
| Apr 15, 2026 | New CVE Received | [email protected] |
Volerion