Executive brief
Nor2-io heim-mcp is a tool used to manage and deploy backend applications via AI agents. A security flaw allows a local attacker to execute unauthorized system commands by providing specially crafted input to the application's deployment tools. This could lead to a full system takeover or unauthorized access to sensitive data on the host machine.
Technical details
The heim-mcp server is vulnerable to OS command injection due to the unsafe use of child_process.exec with user-controlled input in the new_heim_application, deploy_heim_application, and deploy_heim_application_to_cloud tools. Specifically, the registerTools function in src/tools.ts interpolates untrusted parameters—such as path, name, and version—directly into shell command strings. An attacker with local access can provide input containing shell metacharacters (e.g., ;, &, |) to execute arbitrary commands. The vulnerability has been addressed in commit c321d8af25f77668781e6ccb43a1336f9185df37 by migrating from child_process.exec to child_process.execFile, which handles arguments as an array and avoids shell interpretation.
Affected products
- Nor2-io heim-mcp <= 0.1.3
Timeline
- 2026-03-11: disclosed: Issue reported to vendor via GitHub issue and pull request
- 2026-03-23: patched: Fix merged into main branch
- 2026-04-05: advisory: CVE published
References
- https://github.com/Nor2-io/heim-mcp/
- https://github.com/Nor2-io/heim-mcp/commit/c321d8af25f77668781e6ccb43a1336f9185df37
- https://github.com/Nor2-io/heim-mcp/issues/1
- https://github.com/Nor2-io/heim-mcp/pull/2
- https://github.com/user-attachments/files/25889482/heim-mcp_bug.pdf
- https://vuldb.com/submit/784862
- https://vuldb.com/vuln/355394