What is CVE-2026-75011?
CVE-2026-75011 is a command injection vulnerability found in the execAsync function within the index.js file of kylecui NetForensicMCP 2.1.0. Remote attackers can exploit this by manipulating the interface/protocol argument to execute arbitrary commands on the system. Affected users should apply the security patch immediately or implement temporary mitigations.
Azərbaycanca: CVE-2026-75011, kylecui NetForensicMCP 2.1.0 versiyasının index.js faylındakı execAsync funksiyasında aşkarlanmış command injection zəifliyidir. Bu zəiflik uzaqdan hücum edən şəxsə interface/protocol arqumentini manipulyasiya edərək sistemdə ixtiyari əmrlər icra etməyə imkan verir. Məhsuldan istifadə edənlər təcili olaraq təhlükəsizlik yeniləməsini tətbiq etməli və ya müvəqqəti mühafizə tədbirləri görməlidirlər.
Related CVEs
link basis: same weakness class CWE-77
FAQ2
Which product and version is affected by CVE-2026-75011?
The vulnerability was discovered in the index.js file of kylecui NetForensicMCP version 2.1.0.
How can an attacker exploit CVE-2026-75011?
A remote attacker can manipulate the interface/protocol argument to execute arbitrary commands on the system via the execAsync function.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.