CVE-2026-102911 Security Alert: CRITICAL Vulnerability

Urgent: CVE-2026-102911 requires immediate attention.

· 7 min read

Executive Summary

CVE-2026-102911 is a critical remote command injection flaw in zosmaai pi-llm-wiki up to 0.11.7, affecting the wiki_capture_source MCP tool in mcp/index.ts. A manipulated url argument can trigger OS command execution on the host running the service. The issue is rated CVSS 9.9. Although it is not currently in CISA KEV and has not been confirmed exploited in the wild, an exploit has been published, so exposure should be treated as urgent.

The documented fix is version 0.11.8, which includes patch 360867034e79175b45c8e04a98e4ca712bbaca35. If you run this component in production, assume remote compromise is possible until patched.

Immediate Action

  • Upgrade immediately to zosmaai pi-llm-wiki 0.11.8 or later. If you cannot patch within hours, isolate or disable the wiki_capture_source MCP tool.
  • Restrict network access to the service. Put it behind a private network, VPN, or allowlist only trusted callers until remediation is complete.
  • Rollback if needed to a known-safe deployment that does not expose the vulnerable MCP endpoint, or disable the feature flag/module entirely.
  • Review logs for suspicious url values, shell metacharacters, unexpected outbound requests, or child-process activity from the service account.
  • Rotate secrets if the service had access to API keys, tokens, SSH keys, or cloud credentials. Assume they may be exposed if the host was reachable.
  • Vendor advisory: TODO: link to vendor advisory / release notes

Affected Versions

  • zosmaai pi-llm-wiki <= 0.11.7 vulnerable
  • zosmaai pi-llm-wiki 0.11.8+ safe, based on the published fix
  • wiki_capture_source MCP tool in mcp/index.ts is the affected component

Resolution Guide

JavaScript / npm

npm install zosmaai-pi-llm-wiki@0.11.8
# or
npm i zosmaai-pi-llm-wiki@0.11.8 --save-exact

yarn add zosmaai-pi-llm-wiki@0.11.8
pnpm add zosmaai-pi-llm-wiki@0.11.8

Python / pip / pipx (only if you vendor or wrap this component)

pip install --upgrade zosmaai-pi-llm-wiki==0.11.8
pipx upgrade zosmaai-pi-llm-wiki

Java / Maven / Gradle (if the package is mirrored or embedded in your build)

<dependency>
  <groupId>TODO.groupId</groupId>
  <artifactId>TODO.artifactId</artifactId>
  <version>0.11.8</version>
</dependency>
implementation("TODO.group:TODO.artifact:0.11.8")

Linux package managers (if distributed as a system package)

sudo apt update
sudo apt install --only-upgrade TODO-package-name

sudo yum update TODO-package-name
# or
sudo dnf update TODO-package-name

Docker

docker pull TODO-registry/zosmaai-pi-llm-wiki:0.11.8
docker run --rm TODO-registry/zosmaai-pi-llm-wiki:0.11.8

Hardening / temporary mitigation

# Example: disable the vulnerable MCP tool if your app supports feature flags
export DISABLE_WIKI_CAPTURE_SOURCE=1

# Example: run the service with no shell access and minimal privileges
docker run --read-only --cap-drop=ALL --security-opt no-new-privileges \
  --network=none TODO-registry/zosmaai-pi-llm-wiki:0.11.7

Minimal code fix pattern — avoid passing user-controlled URLs to shell commands. Use a strict allowlist and safe process APIs:

// BAD: shell interpolation
exec(`curl ${url}`);

// BETTER: validate and avoid shell
const allowed = new Set(["https://example.com", "https://docs.example.com"]);
if (!allowed.has(url)) throw new Error("Blocked URL");

spawn("curl", ["--fail", "--silent", "--show-error", url], {
  shell: false
});

Detection & Verification

Check installed version

npm ls zosmaai-pi-llm-wiki
node -p "require('./package.json').dependencies?.['zosmaai-pi-llm-wiki'] || require('./package.json').devDependencies?.['zosmaai-pi-llm-wiki']"

Find the vulnerable file and tool

grep -RIn "wiki_capture_source\|mcp/index.ts\|exec(\|spawn(\|child_process" .

Dependency audit

npm audit
yarn audit
pnpm audit

Verify the fix

npm ls zosmaai-pi-llm-wiki
# Confirm version is 0.11.8 or later

grep -RIn "mcp/index.ts" node_modules/zosmaai-pi-llm-wiki
# Confirm the patched code no longer shells out with raw url input

Runtime checks

# Look for suspicious process launches from the service account
ps auxf | grep -E 'curl|sh|bash|node'

# Check logs for malformed URLs or shell metacharacters
grep -RInE '(\&\&|\||;|\$\( |`|<|>)' /var/log /app/logs 2>/dev/null

Risk and Impact

This flaw can let a remote attacker run arbitrary operating-system commands on the machine hosting the service. In a small team environment, that can mean theft of source code, API keys, database credentials, or deployment tokens, plus tampering with builds and production data.

The blast radius depends on what the service can reach. If the process has access to internal networks, mounted volumes, or cloud metadata, an attacker may pivot beyond the original app and compromise other systems.

Keep reading