← back
CVE-2025-53100

RestDB's Codehooks.io MCP Server Vulnerable to Command Injection

CVSS 8.6 HIGHEPSS 1.3%CWE-78
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 8.6EPSS 1.3%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
01 Jul 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
RestDB's Codehooks.io MCP Server is an MCP server on the Codehooks.io platform. Prior to version 0.2.2, the MCP server is written in a way that is vulnerable to command injection attacks as part of some of its MCP Server tools definition and implementation. This could result in a user initiated remote command injection attack on a running MCP Server. This issue has been patched in version 0.2.2.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N