Executive brief
MiniCode, an AI-powered coding assistant, is vulnerable to a flaw that allows attackers to execute malicious commands on a user's computer. By including a hidden configuration file in a project folder, an attacker can trick the software into running unauthorized code as soon as the user opens that project. This could lead to the theft of sensitive data, such as API keys and login tokens, or full control over the user's development environment.
Technical details
A command injection vulnerability exists in LiuMengxuan04 MiniCode 0.1.0 due to the insecure handling of Model Context Protocol (MCP) configuration files. The application automatically loads and executes commands defined in a project-local '.mcp.json' file using 'child_process.spawn' without user confirmation or trust validation. An attacker can exploit this by tricking a user into opening a malicious repository, leading to arbitrary code execution or the exfiltration of environment variables (like ANTHROPIC_API_KEY) via interpolated HTTP headers. A pull request (#37) has been submitted to require explicit user trust before loading project-specific MCP configurations.
Affected products
- LiuMengxuan04 MiniCode 0.1.0
Timeline
- 2026-06-12: disclosed: Vulnerability reported on GitHub issues
- 2026-06-22: patched: Pull request submitted to fix the issue
- 2026-07-18: advisory: CVE published
References
- https://gist.github.com/menelausx/b42381d2788a334cba8cda43f52e2a28
- https://github.com/LiuMengxuan04/MiniCode/
- https://github.com/LiuMengxuan04/MiniCode/issues/35
- https://github.com/LiuMengxuan04/MiniCode/pull/37
- https://vuldb.com/cve/CVE-2026-16133
- https://vuldb.com/submit/856976
- https://vuldb.com/vuln/379853