CVE-2026-102911 Security Alert: CRITICAL Vulnerability
Urgent: CVE-2026-102911 requires immediate attention.
· 7 min read
Executive Summary
CVE-2026-102911 is a critical remote command injection flaw in zosmaai pi-llm-wiki up to 0.11.7, affecting the wiki_capture_source MCP tool in mcp/index.ts. A manipulated url argument can trigger OS command execution on the host running the service. The issue is rated CVSS 9.9. Although it is not currently in CISA KEV and has not been confirmed exploited in the wild, an exploit has been published, so exposure should be treated as urgent.
The documented fix is version 0.11.8, which includes patch 360867034e79175b45c8e04a98e4ca712bbaca35. If you run this component in production, assume remote compromise is possible until patched.
Immediate Action
- Upgrade immediately to
zosmaai pi-llm-wiki 0.11.8or later. If you cannot patch within hours, isolate or disable thewiki_capture_sourceMCP tool. - Restrict network access to the service. Put it behind a private network, VPN, or allowlist only trusted callers until remediation is complete.
- Rollback if needed to a known-safe deployment that does not expose the vulnerable MCP endpoint, or disable the feature flag/module entirely.
- Review logs for suspicious
urlvalues, shell metacharacters, unexpected outbound requests, or child-process activity from the service account. - Rotate secrets if the service had access to API keys, tokens, SSH keys, or cloud credentials. Assume they may be exposed if the host was reachable.
- Vendor advisory: TODO: link to vendor advisory / release notes
Affected Versions
zosmaai pi-llm-wiki <= 0.11.7vulnerablezosmaai pi-llm-wiki 0.11.8+safe, based on the published fixwiki_capture_sourceMCP tool inmcp/index.tsis the affected component
Resolution Guide
JavaScript / npm
npm install zosmaai-pi-llm-wiki@0.11.8
# or
npm i zosmaai-pi-llm-wiki@0.11.8 --save-exact
yarn add zosmaai-pi-llm-wiki@0.11.8
pnpm add zosmaai-pi-llm-wiki@0.11.8
Python / pip / pipx (only if you vendor or wrap this component)
pip install --upgrade zosmaai-pi-llm-wiki==0.11.8
pipx upgrade zosmaai-pi-llm-wiki
Java / Maven / Gradle (if the package is mirrored or embedded in your build)
<dependency>
<groupId>TODO.groupId</groupId>
<artifactId>TODO.artifactId</artifactId>
<version>0.11.8</version>
</dependency>
implementation("TODO.group:TODO.artifact:0.11.8")
Linux package managers (if distributed as a system package)
sudo apt update
sudo apt install --only-upgrade TODO-package-name
sudo yum update TODO-package-name
# or
sudo dnf update TODO-package-name
Docker
docker pull TODO-registry/zosmaai-pi-llm-wiki:0.11.8
docker run --rm TODO-registry/zosmaai-pi-llm-wiki:0.11.8
Hardening / temporary mitigation
# Example: disable the vulnerable MCP tool if your app supports feature flags
export DISABLE_WIKI_CAPTURE_SOURCE=1
# Example: run the service with no shell access and minimal privileges
docker run --read-only --cap-drop=ALL --security-opt no-new-privileges \
--network=none TODO-registry/zosmaai-pi-llm-wiki:0.11.7
Minimal code fix pattern — avoid passing user-controlled URLs to shell commands. Use a strict allowlist and safe process APIs:
// BAD: shell interpolation
exec(`curl ${url}`);
// BETTER: validate and avoid shell
const allowed = new Set(["https://example.com", "https://docs.example.com"]);
if (!allowed.has(url)) throw new Error("Blocked URL");
spawn("curl", ["--fail", "--silent", "--show-error", url], {
shell: false
});
Detection & Verification
Check installed version
npm ls zosmaai-pi-llm-wiki
node -p "require('./package.json').dependencies?.['zosmaai-pi-llm-wiki'] || require('./package.json').devDependencies?.['zosmaai-pi-llm-wiki']"
Find the vulnerable file and tool
grep -RIn "wiki_capture_source\|mcp/index.ts\|exec(\|spawn(\|child_process" .
Dependency audit
npm audit
yarn audit
pnpm audit
Verify the fix
npm ls zosmaai-pi-llm-wiki
# Confirm version is 0.11.8 or later
grep -RIn "mcp/index.ts" node_modules/zosmaai-pi-llm-wiki
# Confirm the patched code no longer shells out with raw url input
Runtime checks
# Look for suspicious process launches from the service account
ps auxf | grep -E 'curl|sh|bash|node'
# Check logs for malformed URLs or shell metacharacters
grep -RInE '(\&\&|\||;|\$\( |`|<|>)' /var/log /app/logs 2>/dev/null
Risk and Impact
This flaw can let a remote attacker run arbitrary operating-system commands on the machine hosting the service. In a small team environment, that can mean theft of source code, API keys, database credentials, or deployment tokens, plus tampering with builds and production data.
The blast radius depends on what the service can reach. If the process has access to internal networks, mounted volumes, or cloud metadata, an attacker may pivot beyond the original app and compromise other systems.