CVE-2026-16133

A flaw has been found in LiuMengxuan04 MiniCode 0.1.0. Affected by this vulnerability is the function child_process.spawn of the file mcp.ts. Executing a manipulation can lead to command injection. The attack can be launched remotely. The attack requires a high level of complexity. The exploitation appears to be difficult. The exploit has been published and may be used. The pull request to fix this issue awaits acceptance.
Configurations

No configuration.

History

18 Jul 2026, 19:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-18 19:17

Updated : 2026-07-20 19:17


NVD link : CVE-2026-16133

Mitre link : CVE-2026-16133

CVE.ORG link : CVE-2026-16133


JSON object : View

Products Affected

No product.

CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')