Junglewise Threat Intelligence

CVE-2026-7600: yii2-mcp-server command injection in MCP interface

CVE-2026-7600 · Severity: low · CVSS 3.1 · Published 2026-05-02

Vendors: npm.

Executive brief

yii2-mcp-server is a Node.js tool that provides a Model Context Protocol interface for Yii2 PHP framework projects, allowing remote execution of Yii console commands. A command injection vulnerability in the MCP tool handlers allows authenticated attackers to inject shell metacharacters and execute arbitrary operating system commands with the privileges of the server process, leading to full host compromise including data theft, data modification, and service disruption.

Technical details

The vulnerability is a classic command injection (CWE-78) in the yii2-mcp-server MCP interface handler. The yii_command_help and yii_execute_command tools construct PHP CLI commands by directly concatenating user-supplied arguments into shell command strings (e.g., `php yii help ${command}` and `php yii ${command} ${args.join(' ')}`) and execute them via Node.js child_process.exec() without escaping or argument vectorization. An attacker with network access to the MCP server and valid authentication (PR:L) can inject shell metacharacters like `;`, `|`, `&`, or backticks to execute arbitrary OS commands. The same pattern affects additional command-execution tools including createMigration, generateCrud, generateModel, and tailLogs. No patch is available as of the report date.

Affected products

  • ArtMin96 yii2-mcp-server 1.0.2 and earlier

Timeline

  • 2026-04-15: disclosed: Vulnerability reported to GitHub as issue #3
  • 2026-05-02: advisory: CVE-2026-7600 published; GHSA-gc8w-x73w-p4rh advisory published
  • 2026-05-07: other: Exploit code published on GitHub (BruceJqs/public_exp)

References