Jaaz 1.0.30 contains a remote code execution vulnerability in its MCP STDIO command execution handling. A remote attacker can send crafted network requests to the network-accessible Jaaz application, causing attacker-controlled commands to be executed on the server. Successful exploitation results in arbitrary command execution within the context of the Jaaz service, potentially allowing full compromise of the affected system.
History

Wed, 15 Apr 2026 22:45:00 +0000

Type Values Removed Values Added
Title Remote Command Execution via MCP STDIO in Jaaz 1.0.30

Wed, 15 Apr 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Jaaz
Jaaz jaaz
Vendors & Products Jaaz
Jaaz jaaz

Wed, 15 Apr 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-77
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 15 Apr 2026 15:30:00 +0000

Type Values Removed Values Added
Description Jaaz 1.0.30 contains a remote code execution vulnerability in its MCP STDIO command execution handling. A remote attacker can send crafted network requests to the network-accessible Jaaz application, causing attacker-controlled commands to be executed on the server. Successful exploitation results in arbitrary command execution within the context of the Jaaz service, potentially allowing full compromise of the affected system.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-04-15T17:56:48.614Z

Reserved: 2026-03-04T00:00:00.000Z

Link: CVE-2026-30616

cve-icon Vulnrichment

Updated: 2026-04-15T17:56:44.862Z

cve-icon NVD

Status : Received

Published: 2026-04-15T16:16:36.293

Modified: 2026-04-15T18:16:59.747

Link: CVE-2026-30616

cve-icon Redhat

No data.