Back to CVE List

CVE-2026-26015

CRITICAL SEVERITY

CVSS Score & Metrics

Base Score
9.8 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Vulnerability Description

DocsGPT is a GPT-powered chat for documentation. From version 0.15.0 to before version 0.16.0, an attacker accessing both the official DocsGPT website or any local and public deployment, can craft a malicious payload bypassing the "MCP test" behavior to achieve arbitrary remote code execution (RCE). This issue has been patched in version 0.16.0.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-77
Source
NVD
Vendor
arc53
Product
DocsGPT

External References

Discussion (0)

Add Comment

No comments yet. Be the first!