CVE-2025-58062

LSTM-Kirigaya's openmcp-client is a vscode plugin for mcp developer. Prior to version 0.1.12, when users on a Windows platform connect to an attacker controlled MCP server, attackers could provision a malicious authorization server endpoint to silently achieve an OS command injection attack in the open() invocation, leading to client system compromise. This issue has been patched in version 0.1.12.
CVSS

No CVSS.

Configurations

No configuration.

History

28 Aug 2025, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-28 23:15

Updated : 2025-08-29 16:24


NVD link : CVE-2025-58062

Mitre link : CVE-2025-58062

CVE.ORG link : CVE-2025-58062


JSON object : View

Products Affected

No product.

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')