CVE-2026-7064High· 7.3▾ MidnightPoC availableA flaw has been found in AgentDeskAI browser-tools-mcp up to 1.2.0. This issue affects some unknown processing of the file browser-tools-server/browser-connector.ts. Executing a manipulation can lead to os command injection. The attack m…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 40.2 · likelihood 0.4 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
2.1%
A flaw has been found in AgentDeskAI browser-tools-mcp up to 1.2.0. This issue affects some unknown processing of the file browser-tools-server/browser-connector.ts. Executing a manipulation can lead to os command injection. The attack may be performed from remote. The exploit has been published and may be used. Upgrading to version 2.0.0 is capable of addressing this issue. It is recommended to upgrade the affected component.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-14586Medium· 6.3A vulnerability was determined in TOTOLINK X5000R 9.1.0cu.2089_B20211224
CVE-2025-59834Critical· 9.8ADB MCP Server is a MCP (Model Context Protocol) server for interacting with Android devices through ADB
CVE-2025-15472High· 7.2A flaw has been found in TRENDnet TEW-811DRU 1.0.2.0
CVE-2026-102911Critical· 9.9A flaw has been found in zosmaai pi-llm-wiki up to 0.11.7
CVE-2026-102906Medium· 6.3A vulnerability was identified in 0xshariq github-mcp-server up to 52e764a7d66eac1726fce02ca7bb5a638571801a
CVE-2026-102874High· 7.3A vulnerability was identified in HKUDS AnyTool 0.1.0