CVE-2026-78430 - sworddut mcp-ffmpeg-helper Tool handlers.ts handleToolCall os command injection
Brief
CVE ID : CVE-2026-78430
Published : Aug. 24, 2026, 8:17 p. m.
- 54 minutes ago
Description : A vulnerability was detected in sworddut mcp-ffmpeg-helper 0.
- 0/0.
- 1/0.
- 1. This affects the function handleToolCall of the file src/tools/handlers. ts of the component Tool Handler. The manipulation of the argument format results in os command injection. Attacking locally is a requirement. The exploit is now public and may be used.
The project was informed of the problem early through an issue report but has not responded yet.
Severity: 5.3
- MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
