216.73.217.22

CVE-2025-53100

· Published 01/07/2025 18:15 · Modified 01/07/2025 18:15

Labels: CVE-2025-53100 2025-07-01CVE-2025-53100CWE-78[email protected]

Essential information

Published
01/07/2025 18:15
Modified
01/07/2025 18:15
Author
Creator
CVSS
8.6 HIGH (v3) 8.6 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

RestDB's Codehooks.io MCP Server is an MCP server on the Codehooks.io platform. Prior to version 0.2.2, the MCP server is written in a way that is vulnerable to command injection attacks as part of some of its MCP Server tools definition and implementation. This could result in a user initiated remote command injection attack on a running MCP Server. This issue has been patched in version 0.2.2.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
restdb / codehooks mcp server cpe:2.3:a:restdb:codehooks_mcp_server:<0.2.2:*:*:*:*:*:*:*

References