CVE-2026-75130
Received Received - Intake

Prompt Injection in Context7 AI Coding Agent

Vulnerability report for CVE-2026-75130, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-18

Last updated on: 2026-08-18

Assigner: VulnCheck

Description

Context7 through 2.1.2 contains a prompt injection vulnerability that allows attackers to execute malicious instructions in connected AI coding agents by injecting unsanitized content through the Custom AI Instructions feature served via the MCP server. Attackers can poison the custom instructions to exfiltrate credentials from environment files to an attacker-controlled service and perform destructive file deletion on the victim's machine when the agent makes a routine library documentation request.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-18
Last Modified
2026-08-18
Generated
2026-08-18
AI Q&A
2026-08-18
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
upstash context7 to 2.1.2 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-75130 is a prompt injection vulnerability in Context7 versions up to 2.1.2. It allows attackers to inject malicious instructions through the Custom AI Instructions feature. When AI coding agents request library documentation, the injected instructions are served unsanitized and executed by the agents, leading to credential theft and file deletion.

Detection Guidance

To detect this vulnerability, monitor network traffic for unusual outbound connections from Context7 processes, especially to external servers. Check for unauthorized file modifications or deletions in directories accessed by AI coding agents. Inspect logs for suspicious MCP server requests or responses containing unexpected instructions.

Impact Analysis

This vulnerability can lead to credential theft from environment files, data exfiltration to attacker-controlled servers, and destructive file deletion on your machine. AI coding agents may unknowingly execute malicious instructions when fetching library documentation.

Mitigation Strategies

Immediately update Context7 to the latest patched version (2.1.2 or later). Disable the Custom AI Instructions feature if not required. Implement network segmentation to restrict MCP server communications. Review and audit all AI agent tool access permissions to limit file system and network operations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-75130. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart