CVE-2026-5833 Details
Description
A security vulnerability has been detected in awwaiid mcp-server-taskwarrior up to 1.0.1. This impacts the function server.setRequestHandler of the file index.ts. Such manipulation of the argument Identifier leads to command injection. The attack must be carried out locally. The exploit has been disclosed publicly and may be used. The name of the patch is 1ee3d282debfa0a99afeb41d22c4b2fd5a3148f2. Applying a patch is advised to resolve this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
A command injection vulnerability exists in Awwaiid MCP-Server-Taskwarrior versions through 1.0.1. The issue arises in the 'server.setRequestHandler' function within 'index.ts', where user-controlled input is improperly sanitized before being used in command-line operations. This vulnerability allows local attackers to execute arbitrary commands with the same privileges as the MCP server process.
Users are advised to update to the patched version of Awwaiid MCP-Server-Taskwarrior, which is available on the project's GitHub repository.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 9, 2026CISA-ADP
Assessed Apr 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/awwaiid/mcp-server-taskwarrior/ | [email protected] | ProductSource CodeVendor |
| https://github.com/awwaiid/mcp-server-taskwarrior/commit/1ee3d282debfa0a99afeb41d22c4b2fd5a3148f2 | [email protected] | Source CodeVendor |
| https://github.com/awwaiid/mcp-server-taskwarrior/issues/8 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/awwaiid/mcp-server-taskwarrior/issues/8#issuecomment-4139402095 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/user-attachments/files/25923228/mcp-server-taskwarrior_bug.pdf | [email protected] | |
| https://vuldb.com/submit/789810 | [email protected] | AdvisoryIssue TrackingTechnical Description |
| https://vuldb.com/vuln/356289 | [email protected] | AdvisoryExploitRemedy |
| https://vuldb.com/vuln/356289/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-74 | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') | [email protected] |
| CWE-77 | Improper Neutralization of Special Elements used in a Command ('Command Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| awwaiid mcp-server-taskwarrior | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Data Remediation | [email protected] |
| Apr 9, 2026 | New CVE Received | [email protected] |
Volerion