Unauthenticated command execution via prefix-only shell validation
Published Apr 26, 2026 · Updated Apr 26, 2026
OS command injection in choieastsea simple-openstack-mcp at commit 767b2f4 allows remote attackers to execute commands through its MCP tool. exec_openstack checks only that input starts with openstack, then OpenStackCommander.execute passes the entire string to subprocess.run with shell=True, allowing appended shell metacharacters to escape the intended CLI. Access to the MCP tool is required; successful exploitation runs shell commands as the service account, enabling local file reads or writes and service interruption.
Summary
What happened
OS command injection in choieastsea simple-openstack-mcp at commit 767b2f4 allows remote attackers to execute commands through its MCP tool. exec_openstack checks only that input starts with openstack, then OpenStackCommander.execute passes the entire string to subprocess.run with shell=True, allowing appended shell metacharacters to escape the intended CLI. Access to the MCP tool is required; successful exploitation runs shell commands as the service account, enabling local file reads or writes and service interruption.
The record
- CVE
- CVE-2026-7066
- Published
- Apr 26, 2026
- Updated
- Apr 26, 2026
- Vendor
- choieastsea
- Product
- simple-openstack-mcp
- Classifications
- CWE-78, CWE-77, T1059
- Attack vector
- network
- Privileges
- unauthenticated
Timeline
How it unfolded
- Apr 26, 2026CVE publishedPublication date reported by the CVE source.
- Apr 26, 2026Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=767b2f4a8154cca344344b9725537a58399e6036
What conditions does exploitation require?
What is affected?
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Weakness, pattern, technique
Public exploit references
- GitHub issue JSON-RPC shell-metacharacter proof of conceptproof of concept · unverified
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo