Junglewise Threat Intelligence

CVE-2026-6130: chatboxai Chatbox OS command injection in MCP Server Management

CVE-2026-6130 · Severity: high · CVSS 7.3 · Published 2026-04-12

Executive brief

Chatbox AI, a desktop application for interacting with AI models, contains a vulnerability that allows attackers to execute unauthorized commands on a user's computer. By tricking a user into clicking a malicious link or importing a compromised configuration file, an attacker can gain full control over the user's system. This could lead to the theft of sensitive data, installation of malware, or complete loss of system integrity.

Technical details

An OS command injection vulnerability exists in Chatbox AI up to v1.20.0 within the StdioClientTransport function of src/main/mcp/ipc-stdio-transport.ts. The application fails to validate or sanitize 'command' and 'args' parameters when creating Model Context Protocol (MCP) server configurations. Attackers can exploit this via three vectors: malicious deep links (chatbox://mcp/install), malicious JSON data imports, or XSS in the renderer. Because enabled MCP servers are automatically started upon application launch via mcp_bootstrap.ts, an injected configuration can achieve persistent remote code execution (RCE) without further user interaction after the initial trigger. As of the advisory date, no official patch has been released.

Affected products

  • chatboxai Chatbox AI Chatbox up to 1.20.0

Timeline

  • 2026-04-02: disclosed: Vulnerability reported via GitHub issue #3627
  • 2026-04-12: advisory: CVE-2026-6130 published

References