CVE-2026-102911
A flaw has been found in zosmaai pi-llm-wiki up to 0.11.7. Affected is an unknown function of the file mcp/index.ts of the component wiki_capture_source MCP tool. Executing a manipulation of the argument url can lead to os command injection. The attack can be executed remotely. The exploit has been published and may be used. Upgrading to version 0.11.8 is able to address this issue. This patch is called 360867034e79175b45c8e04a98e4ca712bbaca35. Upgrading the affected component is advised.
CVSS
- Versión: 4.0
- Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Puntuación base: 8.6
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.78%
- Percentil entre todas las CVEs puntuadas: 78
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1210Exploitation of Remote Serviceslateral movement85 % - Impacto principal
T1059Command and Scripting Interpreterexecution90 %
Inyección de comandos del SO (CWE-78) en parámetro URL remoto sin privilegios iniciales. AV:N/PR:L indica acceso autenticado a aplicación web expuesta; impacto VI:H confirma ejecución de código.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-77, CWE-78
Referencias
- https://github.com/zosmaai/pi-llm-wiki/
- https://github.com/zosmaai/pi-llm-wiki/commit/360867034e79175b45c8e04a98e4ca712bbaca35
- https://github.com/zosmaai/pi-llm-wiki/issues/185
- https://github.com/zosmaai/pi-llm-wiki/pull/186
- https://github.com/zosmaai/pi-llm-wiki/releases/tag/v0.11.8
- https://vuldb.com/cve/CVE-2026-102911
- https://vuldb.com/submit/953898
- https://vuldb.com/vuln/411587
- https://vuldb.com/vuln/411587/cti
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-102911",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-102911",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2026-09-30T16:53:08.171233Z"
}
}
],
"cvssMetricV2": [
{
"type": "Secondary",
"source": "cna@vuldb.com",
"cvssData": {
"version": "2.0",
"baseScore": 9,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:S/C:C/I:C/A:C",
"authentication": "SINGLE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "cna@vuldb.com",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 9.9,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 6,
"exploitabilityScore": 3.1
}
],
"cvssMetricV40": [
{
"type": "Secondary",
"source": "cna@vuldb.com",
"cvssData": {
"Safety": "NOT_DEFINED",
"version": "4.0",
"Recovery": "NOT_DEFINED",
"baseScore": 8.6,
"Automatable": "NOT_DEFINED",
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"exploitMaturity": "PROOF_OF_CONCEPT",
"providerUrgency": "NOT_DEFINED",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"privilegesRequired": "LOW",
"subIntegrityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"subAvailabilityImpact": "HIGH",
"vulnAvailabilityImpact": "HIGH",
"availabilityRequirement": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"subConfidentialityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"confidentialityRequirement": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"vulnerabilityResponseEffort": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED"
}
}
]
},
"affected": [
{
"source": "cna@vuldb.com",
"affectedData": [
{
"cpes": [
"cpe:2.3:a:zosmaai:pi-llm-wiki:*:*:*:*:*:*:*:*"
],
"vendor": "zosmaai",
"modules": [
"wiki_capture_source MCP tool"
],
"product": "pi-llm-wiki",
"versions": [
{
"status": "affected",
"version": "0.11.0"
},
{
"status": "affected",
"version": "0.11.1"
},
{
"status": "affected",
"version": "0.11.2"
},
{
"status": "affected",
"version": "0.11.3"
},
{
"status": "affected",
"version": "0.11.4"
},
{
"status": "affected",
"version": "0.11.5"
},
{
"status": "affected",
"version": "0.11.6"
},
{
"status": "affected",
"version": "0.11.7"
},
{
"status": "unaffected",
"version": "0.11.8"
}
]
}
]
}
],
"published": "2026-09-30T04:18:28.580",
"references": [
{
"url": "https://github.com/zosmaai/pi-llm-wiki/",
"source": "cna@vuldb.com"
},
{
"url": "https://github.com/zosmaai/pi-llm-wiki/commit/360867034e79175b45c8e04a98e4ca712bbaca35",
"source": "cna@vuldb.com"
},
{
"url": "https://github.com/zosmaai/pi-llm-wiki/issues/185",
"source": "cna@vuldb.com"
},
{
"url": "https://github.com/zosmaai/pi-llm-wiki/pull/186",
"source": "cna@vuldb.com"
},
{
"url": "https://github.com/zosmaai/pi-llm-wiki/releases/tag/v0.11.8",
"source": "cna@vuldb.com"
},
{
"url": "https://vuldb.com/cve/CVE-2026-102911",
"source": "cna@vuldb.com"
},
{
"url": "https://vuldb.com/submit/953898",
"source": "cna@vuldb.com"
},
{
"url": "https://vuldb.com/vuln/411587",
"source": "cna@vuldb.com"
},
{
"url": "https://vuldb.com/vuln/411587/cti",
"source": "cna@vuldb.com"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "cna@vuldb.com",
"description": [
{
"lang": "en",
"value": "CWE-77"
},
{
"lang": "en",
"value": "CWE-78"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A flaw has been found in zosmaai pi-llm-wiki up to 0.11.7. Affected is an unknown function of the file mcp/index.ts of the component wiki_capture_source MCP tool. Executing a manipulation of the argument url can lead to os command injection. The attack can be executed remotely. The exploit has been published and may be used. Upgrading to version 0.11.8 is able to address this issue. This patch is called 360867034e79175b45c8e04a98e4ca712bbaca35. Upgrading the affected component is advised."
}
],
"lastModified": "2026-09-30T17:16:41.040",
"sourceIdentifier": "cna@vuldb.com"
}