Skip to main content
CRITICAL

CVE-2026-102911

CVSS v3

9.9

CRITICAL

EPSS Score

1.8 %

exploit probability, as of 2026-09-30

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

A flaw has been found in zosmaai pi-llm-wiki up to 0.11.7. Affected is an unknown function of the file mcp/index.ts of the component wiki_capture_source MCP tool. Executing a manipulation of the argument url can lead to os command injection. The attack can be executed remotely. The exploit has been published and may be used. Upgrading to version 0.11.8 is able to address this issue. This patch is called 360867034e79175b45c8e04a98e4ca712bbaca35. Upgrading the affected component is advised.

Technical details

CVSS v3 Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Published
2026-09-30
Last Modified
2026-09-30

Frequently asked questions

What is CVE-2026-102911?

A flaw has been found in zosmaai pi-llm-wiki up to 0.11.7. Affected is an unknown function of the file mcp/index.ts of the component wiki_capture_source MCP tool. Executing a manipulation of the argument url can lead to os command injection. The attack can be executed remotely. The exploit has been published and may be used. Upgrading to version 0.11.8 is able to address this issue. This patch is called 360867034e79175b45c8e04a98e4ca712bbaca35. Upgrading the affected component is advised.

Is CVE-2026-102911 actively exploited?

Active exploitation of CVE-2026-102911 has not been confirmed. Its EPSS score was 1.8% on 2026-09-30, the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2026-102911?

CVE-2026-102911 has a CVSS v3 base score of 9.9 (CRITICAL severity), with vector string CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H.

Is CVE-2026-102911 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key