Junglewise Threat Intelligence

CVE-2026-19263: INQUIRELAB mcp-bridge-api command injection in Servers Endpoint

CVE-2026-19263 · Severity: high · CVSS 7.3 · Published 2026-08-08

Executive brief

mcp-bridge-api is a REST API proxy that connects to multiple Model Context Protocol servers for secure tool execution. The unauthenticated POST /servers endpoint accepts arbitrary command and arguments from remote callers and passes them directly to the operating system without validation or allowlisting, allowing attackers to execute arbitrary processes on the host server with the service's privileges.

Technical details

The vulnerability is a command injection flaw in the mcp-bridge.js file's POST /servers endpoint handler. The vulnerable code accepts user-supplied `command` and `args` parameters directly from the request body, constructs a config object, and passes them to startServer() which spawns the process via child_process.spawn() with shell enabled on non-Windows systems. The attack requires no authentication or special preconditions—any remote client with network access to the API can trigger process execution. An attacker can execute arbitrary local programs with the privileges of the mcp-bridge service process, achieving remote code execution (RCE). The affected versions include commits up to b30a82aa1d1d1139e0de846c41c8aadee6e06114, with rolling release versioning; a fix via pull request is awaiting acceptance.

Affected products

  • INQUIRELAB mcp-bridge-api up to b30a82aa1d1d1139e0de846c41c8aadee6e06114

Timeline

  • 2026-08-08: disclosed
  • other: Pull request to fix awaiting acceptance

References