CVE-2026-30616
Received Received - Intake
Remote Code Execution in Jaaz 1.0.30 via MCP STDIO Command

Publication date: 2026-04-15

Last updated on: 2026-04-15

Assigner: MITRE

Description
Jaaz 1.0.30 contains a remote code execution vulnerability in its MCP STDIO command execution handling. A remote attacker can send crafted network requests to the network-accessible Jaaz application, causing attacker-controlled commands to be executed on the server. Successful exploitation results in arbitrary command execution within the context of the Jaaz service, potentially allowing full compromise of the affected system.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-04-15
Last Modified
2026-04-15
Generated
2026-06-16
AI Q&A
2026-04-15
EPSS Evaluated
2026-06-15
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
jaaz jaaz 1.0.30
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-77 The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

Jaaz 1.0.30 contains a remote code execution vulnerability in its MCP STDIO command execution handling.

A remote attacker can send specially crafted network requests to the Jaaz application, which is accessible over the network.

These crafted requests cause commands controlled by the attacker to be executed on the server running Jaaz.

This means the attacker can run arbitrary commands within the context of the Jaaz service.

Impact Analysis

Successful exploitation of this vulnerability can lead to arbitrary command execution on the affected system.

This potentially allows an attacker to fully compromise the system running the Jaaz service.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-30616. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart