CVE-2026-7066
choieastsea simple-openstack-mcp server.py exec_openstack os command injection
CVSS Score
7.3
EPSS Score
0.0%
EPSS Percentile
0th
A vulnerability was found in choieastsea simple-openstack-mcp up to 767b2f4a8154cca344344b9725537a58399e6036. The affected element is the function exec_openstack of the file server.py. The manipulation results in os command injection. It is possible to launch the attack remotely. The exploit has been made public and could be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The project was informed of the problem early through an issue report but has not responded yet.
| CWE | CWE-78 CWE-77 |
| Vendor | choieastsea |
| Product | simple-openstack-mcp |
| Published | Apr 26, 2026 |
Stay Ahead of the Next One
Get instant alerts for choieastsea simple-openstack-mcp
Be the first to know when new high vulnerabilities affecting choieastsea simple-openstack-mcp are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
choieastsea / simple-openstack-mcp
767b2f4a8154cca344344b9725537a58399e6036
References
Credits
๐ MidA (VulDB User) VulDB CNA Team