๐Ÿ” CVE Alert

CVE-2026-7590

HIGH 7.3

eyal-gor p_69_branch_monkey_mcp Preview Endpoint advanced.py os command injection

CVSS Score
7.3
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability was identified in eyal-gor p_69_branch_monkey_mcp up to 69bc71874ce40050ef45fde5a435855f18af3373. The affected element is an unknown function of the file branch_monkey_mcp/bridge_and_local_actions/routes/advanced.py of the component Preview Endpoint. Such manipulation of the argument dev_script leads to os command injection. The attack can be launched remotely. The exploit is publicly available and might be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The project was informed of the problem early through an issue report but has not responded yet.

CWE CWE-78 CWE-77
Vendor eyal-gor
Product p_69_branch_monkey_mcp
Published May 1, 2026
Stay Ahead of the Next One

Get instant alerts for eyal-gor p_69_branch_monkey_mcp

Be the first to know when new high vulnerabilities affecting eyal-gor p_69_branch_monkey_mcp are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

eyal-gor / p_69_branch_monkey_mcp
69bc71874ce40050ef45fde5a435855f18af3373

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/360543 vuldb.com: https://vuldb.com/vuln/360543/cti vuldb.com: https://vuldb.com/submit/804413 github.com: https://github.com/eyal-gor/p_69_branch_monkey_mcp/issues/8 github.com: https://github.com/eyal-gor/p_69_branch_monkey_mcp/

Credits

๐Ÿ” LargeW (VulDB User) VulDB CNA Team