Sceawere

Vulnerability Detail

CVE-2026-102911UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

OS Command Injection in pi-llm-wiki

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.9
Creation Date
3h ago
Vendor
zosmaai
Product
pi-llm-wiki
Attack Type
OS Command Injection
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

A flaw has been found in zosmaai pi-llm-wiki up to 0.11.7. Affected is an unknown function of the file mcp/index.ts of the component wiki_capture_source MCP tool. Executing a manipulation of the argument url can lead to os command injection. The attack can be executed remotely. The exploit has been published and may be used. Upgrading to version 0.11.8 is able to address this issue. This patch is called 360867034e79175b45c8e04a98e4ca712bbaca35. Upgrading the affected component is advised.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.9",
  "pubDate": "2026-09-30T04:18:28.580Z",
  "pubdate": "2026-09-30T04:18:28.580Z",
  "executiveSummary": "A critical OS command injection vulnerability has been identified in the zosmaai pi-llm-wiki component, specifically within the wiki_capture_source MCP tool. This flaw allows an unauthenticated remote attacker to execute arbitrary system commands on the underlying host operating system by manipulating the 'url' argument.\nThe vulnerability originates from improper input sanitization within the 'mcp/index.ts' file, where user-supplied input is passed directly to system-level functions. The impact is severe, as successful exploitation results in full remote code execution, potentially leading to unauthorized data access, system compromise, or complete service disruption.\nThe vulnerability affects all versions of pi-llm-wiki up to 0.11.7. Because proof-of-concept exploit code has been publicly disclosed, the risk of active exploitation is significant. Users are advised to upgrade to version 0.11.8 immediately to apply the patch identified as 360867034e79175b45c8e04a98e4ca712bbaca35.",
  "technicalDetails": "The vulnerability resides in the 'wiki_capture_source' MCP tool component of the pi-llm-wiki software, specifically within the 'mcp/index.ts' source file. The root cause of the flaw is a failure to implement robust input validation or parameterization on the 'url' argument before it is utilized in system-level execution contexts. In many Node.js or similar environments, this often manifests as passing unsanitized input to functions such as 'child_process.exec' or 'child_process.spawn'.\nThe attack flow begins when an attacker identifies the endpoint exposed by the 'wiki_capture_source' tool. By injecting shell metacharacters or command separators (such as ';', '&', or '|') into the 'url' parameter, an attacker can escape the intended function scope and append arbitrary shell commands. Because the application fails to validate the structure or protocol of the provided URL, it blindly executes the injected command sequence with the privileges of the service user running the pi-llm-wiki process.\nBecause the attack is executable remotely, it does not require authentication or localized access to the server, significantly lowering the barrier for exploitation. An attacker can craft a malicious URL string that, when processed by the server, results in the execution of system binaries (e.g., '/bin/sh', 'curl', or 'wget').\nThe post-exploitation impact is catastrophic. Upon successful injection, the attacker can leverage the command shell to perform reconnaissance, establish persistence via reverse shells, pivot to internal network segments, or exfiltrate sensitive environment variables, configuration files, and data handled by the LLM component. The ability to execute arbitrary commands means the attacker effectively gains the same authority as the application process, allowing for total system compromise if the service is running with elevated privileges or is not adequately containerized/sandboxed.\nThis vulnerability persists across all versions of pi-llm-wiki up to and including 0.11.7. Remediation requires the application of the official patch, which introduces rigorous input sanitization and forces the use of safer API alternatives that do not invoke a shell interpreter when processing external input."
}
CVE-2026-102911: OS Command Injection in pi-llm-wiki (CRITICAL Severity, CVSS: 9.9) | Sceawere