A weakness has been identified in privsim mcp-test-runner 0.2.0. Impacted is the function child_process.spawn of the file src/index.ts of the component MCP Interface. Executing a manipulation of the argument command can lead to os command injection. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
CVE-2026-7730 is an OS command injection vulnerability in privsim mcp-test-runner 0.2.0 affecting the child_process.spawn function, allowing remote attackers to execute arbitrary commands through manipulated arguments. The vulnerability has a CVSS score of 6.3 and public exploits are available.
يؤثر هذا الضعف على مكون واجهة MCP في privsim mcp-test-runner الإصدار 0.2.0 حيث يمكن للمهاجمين التلاعب بوسائط الأوامر لتنفيذ أوامر نظام التشغيل بشكل تعسفي. تم الإفصاح العام عن الاستغلال مما يزيد من خطر الهجمات الفعلية.
A command injection flaw exists in privsim mcp-test-runner 0.2.0 where the MCP Interface component fails to properly sanitize arguments passed to child_process.spawn, enabling remote OS command execution. Public exploits are available and the vendor has not yet responded to early notification.
Immediately upgrade privsim mcp-test-runner to a patched version beyond 0.2.0 when available. Implement input validation and sanitization for all command arguments passed to child_process.spawn. Apply principle of least privilege to limit process execution capabilities. Monitor for suspicious process spawning activities in logs.
قم بترقية privsim mcp-test-runner فوراً إلى إصدار مصحح عند توفره. طبق التحقق من صحة المدخلات وتعقيمها لجميع وسائط الأوامر المرسلة إلى child_process.spawn. طبق مبدأ الامتيازات الأقل لتقييد قدرات تنفيذ العمليات. راقب الأنشطة المريبة لتوليد العمليات في السجلات.