← Zuruck zu CVEs
CVE-2026-22793
CRITICAL9.6
Beschreibung
5ire is a cross-platform desktop artificial intelligence assistant and model context protocol client. Prior to version 0.15.3, an unsafe option parsing vulnerability in the ECharts Markdown plugin allows any user able to submit ECharts code blocks to execute arbitrary JavaScript code in the renderer context. This can lead to Remote Code Execution (RCE) in environments where privileged APIs (such as Electron’s electron.mcp) are exposed, resulting in full compromise of the host system. Version 0.15.3 patches the issue.
CVE Details
CVSS v3.1 Bewertung9.6
SchweregradCRITICAL
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionREQUIRED
Veroffentlicht1/21/2026
Zuletzt geandert1/29/2026
Quellenvd
Honeypot-Sichtungen0
Betroffene Produkte
5ire:5ire
Schwachen (CWE)
CWE-94
Referenzen
https://github.com/nanbingxyz/5ire/releases/tag/v0.15.3(security-advisories@github.com)
https://github.com/nanbingxyz/5ire/security/advisories/GHSA-wg3x-7c26-97wj(security-advisories@github.com)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.