๐Ÿ” CVE Alert

CVE-2026-102911

CRITICAL 9.9

zosmaai pi-llm-wiki wiki_capture_source MCP tool index.ts os command injection

CVSS Score
9.9
EPSS Score
0.0%
EPSS Percentile
0th

A flaw has been found in zosmaai pi-llm-wiki up to 0.11.7. Affected is an unknown function of the file mcp/index.ts of the component wiki_capture_source MCP tool. Executing a manipulation of the argument url can lead to os command injection. The attack can be executed remotely. The exploit has been published and may be used. Upgrading to version 0.11.8 is able to address this issue. This patch is called 360867034e79175b45c8e04a98e4ca712bbaca35. Upgrading the affected component is advised.

CWE CWE-78 CWE-77
Vendor zosmaai
Product pi-llm-wiki
Published Sep 30, 2026
Stay Ahead of the Next One

Get instant alerts for zosmaai pi-llm-wiki

Be the first to know when new critical vulnerabilities affecting zosmaai pi-llm-wiki are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

zosmaai / pi-llm-wiki
0.11.0 0.11.1 0.11.2 0.11.3 0.11.4 0.11.5 0.11.6 0.11.7

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/411587 vuldb.com: https://vuldb.com/vuln/411587/cti vuldb.com: https://vuldb.com/cve/CVE-2026-102911 vuldb.com: https://vuldb.com/submit/953898 github.com: https://github.com/zosmaai/pi-llm-wiki/issues/185 github.com: https://github.com/zosmaai/pi-llm-wiki/pull/186 github.com: https://github.com/zosmaai/pi-llm-wiki/commit/360867034e79175b45c8e04a98e4ca712bbaca35 github.com: https://github.com/zosmaai/pi-llm-wiki/releases/tag/v0.11.8 github.com: https://github.com/zosmaai/pi-llm-wiki/

Credits

๐Ÿ” Xh1Xxhg (VulDB User)