{"id":"GHSA-64vr-4gr2-m642","summary":"automagik-genie has a command injection vulnerability","details":"Command injection vulnerability in automagik-genie 2.5.27 MCP Server allows attackers to execute arbitrary commands via the view_task (aka view) in the readTranscriptFromCommit function in dist/mcp/server.js when a user reads from an external FORGE_BASE_URL.","aliases":["CVE-2026-30635"],"modified":"2026-05-18T15:41:31.167955Z","published":"2026-05-11T18:31:45Z","database_specific":{"cwe_ids":["CWE-78"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-05-18T15:27:57Z","nvd_published_at":"2026-05-11T18:16:31Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-30635"},{"type":"WEB","url":"https://gist.github.com/spdc-elm/3ddecd10ffa85c5963ab7fe531619875"},{"type":"PACKAGE","url":"https://github.com/automagik-dev/genie"}],"affected":[{"package":{"name":"automagik-genie","ecosystem":"npm","purl":"pkg:npm/automagik-genie"},"versions":["2.5.27"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-64vr-4gr2-m642/GHSA-64vr-4gr2-m642.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}