Junglewise Threat Intelligence

CVE-2026-19958: iatsiuk pptr-mcp code injection in executeCode

CVE-2026-19958 · Severity: medium · CVSS 6.3 · Published 2026-08-16

Executive brief

pptr-mcp is a library that provides MCP integration for browser automation. A code injection vulnerability in the executeCode function allows remote attackers to inject and execute arbitrary code on systems using this library, potentially leading to unauthorized access and system compromise.

Technical details

The vulnerability is a code injection flaw in the executeCode function of the src/vm-executor.ts file within the execute tool component. The vulnerable code fails to properly validate or sanitize input before executing code, allowing an attacker to inject malicious code. The attack vector is network-based and does not require authentication. An attacker can exploit this remotely to achieve arbitrary code execution on the affected system. The vendor has been notified of the issue but has not yet provided a patch.

Affected products

  • iatsiuk pptr-mcp up to 0.2.7

Timeline

  • 2026-08-16: disclosed
  • 2026-08-16: advisory

References