HIGHAi
Verified
Global

NVD HIGH: CVE-2026-6130 — A flaw has been found in chatboxai chatbox up to 1.20.0. This impacts the functi...

·Source: NIST NVD

Updated:

Executive Summary

A flaw has been found in chatboxai chatbox up to 1.20.0. This impacts the function StdioClientTransport of the file src/main/mcp/ipc-stdio-transport.ts of the component Model Context Protocol Server Management System. Executing a manipulation of the argument args/env can lead to os command injection. The attack can be launched remotely. The exploit has been published and may be used. The project w

Analysis

A flaw has been found in chatboxai chatbox up to 1.20.0. This impacts the function StdioClientTransport of the file src/main/mcp/ipc-stdio-transport.ts of the component Model Context Protocol Server Management System. Executing a manipulation of the argument args/env can lead to os command injection. The attack can be launched remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet. CVSS Score: 7.3. Published: 2026-04-12T22:16:09.360.

Indicators of Compromise (1)

CVE (1)
CVE-2026-6130
Source Attribution

Originally published by NIST NVD on Apr 12, 2026. Verified by: NIST.

Related Threats