CVE-2026-3484

A vulnerability was detected in PhialsBasement nmap-mcp-server up to bee6d23547d57ae02460022f7c78ac0893092e38. Affected by this issue is the function child_process.exec of the file src/index.ts of the component Nmap CLI Command Handler. The manipulation results in command injection. The attack may be performed from remote. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The patch is identified as 30a6b9e1c7fa6146f51e28d6ab83a2568d9a3488. It is best practice to apply a patch to resolve this issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:phialsbasement:mcp_nmap_server:*:*:*:*:*:*:*:*

History

05 Mar 2026, 21:32

Type Values Removed Values Added
First Time Phialsbasement
Phialsbasement mcp Nmap Server
CPE cpe:2.3:a:phialsbasement:mcp_nmap_server:*:*:*:*:*:*:*:*
References () https://github.com/PhialsBasement/nmap-mcp-server/ - () https://github.com/PhialsBasement/nmap-mcp-server/ - Product
References () https://github.com/PhialsBasement/nmap-mcp-server/commit/30a6b9e1c7fa6146f51e28d6ab83a2568d9a3488 - () https://github.com/PhialsBasement/nmap-mcp-server/commit/30a6b9e1c7fa6146f51e28d6ab83a2568d9a3488 - Patch
References () https://github.com/PhialsBasement/nmap-mcp-server/issues/7 - () https://github.com/PhialsBasement/nmap-mcp-server/issues/7 - Exploit, Issue Tracking
References () https://github.com/PhialsBasement/nmap-mcp-server/issues/7#issuecomment-3814382570 - () https://github.com/PhialsBasement/nmap-mcp-server/issues/7#issuecomment-3814382570 - Exploit, Issue Tracking
References () https://vuldb.com/?ctiid.348559 - () https://vuldb.com/?ctiid.348559 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.348559 - () https://vuldb.com/?id.348559 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.763773 - () https://vuldb.com/?submit.763773 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.763777 - () https://vuldb.com/?submit.763777 - Third Party Advisory, VDB Entry

03 Mar 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-03 20:16

Updated : 2026-03-05 21:32


NVD link : CVE-2026-3484

Mitre link : CVE-2026-3484

CVE.ORG link : CVE-2026-3484


JSON object : View

Products Affected

phialsbasement

  • mcp_nmap_server
CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')