๐Ÿ” CVE Alert

CVE-2026-105797

HIGH 8.8

SimpleChat: Command injection via authorization-gate ordering flaw (arbitrary process spawn through MCP stdio transport)

CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th

SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions. In versions 0.261.003 and 0.261.027, an authorization ordering flaw in POST /api/user/plugins allows an authenticated low-privileged user to omit the top-level MCP type so that _reject_non_admin_mcp_stdio skips inspection before the type is restored from metadata. The stored personal action can then reach McpPluginFactory.create_connector, and MCPStdioPlugin.connect starts the attacker-selected operating-system process under the application service identity when the action tool is invoked. Exploitation requires personal plugins to be enabled and governance to permit MCP actions, and it can expose or modify secrets and data available to the service or disrupt the service. This issue is fixed in version 0.261.031.

CWE CWE-78 CWE-863
Vendor microsoft
Product simplechat
Ecosystems
Industries
TechnologyEnterprise
Published Oct 6, 2026
Stay Ahead of the Next One

Get instant alerts for microsoft simplechat

Be the first to know when new high vulnerabilities affecting microsoft simplechat are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

microsoft / simplechat
< 0.261.031

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/microsoft/simplechat/security/advisories/GHSA-h4mw-qw8m-5x4j github.com: https://github.com/microsoft/simplechat/commit/73ff7d6998dc4827a0f6ba002386275a7c1ec804