No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 30 Mar 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 30 Mar 2026 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dedeveloper23
Dedeveloper23 codebase-mcp |
|
| Vendors & Products |
Dedeveloper23
Dedeveloper23 codebase-mcp |
Sun, 29 Mar 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been found in DeDeveloper23 codebase-mcp up to 3ec749d237dd8eabbeef48657cf917275792fde6. This vulnerability affects the function getCodebase/getRemoteCodebase/saveCodebase of the file src/tools/codebase.ts of the component RepoMix Command Handler. Such manipulation leads to os command injection. The attack needs to be performed locally. The exploit has been disclosed to the public and may be used. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. The project was informed of the problem early through an issue report but has not responded yet. | |
| Title | DeDeveloper23 codebase-mcp RepoMix codebase.ts saveCodebase os command injection | |
| Weaknesses | CWE-77 CWE-78 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-03-30T14:52:49.798Z
Reserved: 2026-03-27T14:24:26.539Z
Link: CVE-2026-5023
Updated: 2026-03-30T13:14:17.020Z
Status : Awaiting Analysis
Published: 2026-03-29T02:16:17.640
Modified: 2026-03-30T13:26:07.647
Link: CVE-2026-5023
No data.
OpenCVE Enrichment
Updated: 2026-03-30T06:58:41Z