Junglewise Threat Intelligence

CVE-2025-10619: @sequa-ai/sequa-mcp command injection in OAuth server discovery

CVE-2025-10619 · Severity: low · CVSS 3.1 · Published 2025-09-17

Vendors: npm.

Executive brief

Sequa MCP is a library used in AI applications to handle OAuth authentication flows. A command injection vulnerability in the authorization URL handling allows authenticated users to execute arbitrary operating system commands, potentially compromising the application server and any data it processes.

Technical details

A command injection vulnerability (CWE-77) exists in the redirectToAuthorization function of src/helpers/node-oauth-client-provider.ts in @sequa-ai/sequa-mcp up to version 1.0.13. The vulnerability arises from insufficient validation of OAuth server discovery URLs, allowing an attacker with authentication credentials to manipulate the authorization URL parameter and inject OS commands that are executed by the application. The attack requires prior authentication (PR:L) and network access (AV:N), with no user interaction needed. An attacker can achieve limited confidentiality, integrity, and availability impact. The vendor has released version 1.0.14 with URL validation fixes (commit e569815854166db5f71c2e722408f8957fb9e804).

Affected products

  • Sequa AI sequa-mcp up to 1.0.13

Timeline

  • 2025-09-17: disclosed: Advisory published
  • 2025-09-17: patched: Version 1.0.14 released with fix

References