Skip to content
Threat Feed
critical advisory

Remote Code Execution in zosmaai pi-llm-wiki

An OS command injection vulnerability in the wiki_capture_source MCP tool of zosmaai pi-llm-wiki versions up to 0.11.7 allows remote unauthenticated attackers to execute arbitrary commands via the url argument.

CVE search metadata

CVE search record: CVE-2026-102911. Severity: critical. CVSS: 9.9. KEV: no. Product: pi-llm-wiki (<= 0.11.7). Brief: Remote Code Execution in zosmaai pi-llm-wiki. Brief link: https://feed.craftedsignal.io/briefs/2026-09-cve-2026-102911/

The zosmaai pi-llm-wiki project contains a critical OS command injection vulnerability, tracked as CVE-2026-102911, impacting all versions up to and including 0.11.7. The vulnerability resides within the wiki_capture_source functionality implemented in mcp/index.ts. By supplying a maliciously crafted string to the url argument, an attacker can escape the intended input boundaries and execute arbitrary operating system commands on the host machine. Given that the pi-llm-wiki tool is designed to interface with LLM pipelines, it is frequently exposed to external inputs, significantly increasing the risk of exploitation. Publicly available exploit code exists, heightening the immediate threat to organizations running this component in reachable environments. Organizations should upgrade to version 0.11.8 immediately to apply the patch identified as 360867034e79175b45c8e04a98e4ca712bbaca35.

Attack Chain

  1. The attacker identifies an instance of zosmaai pi-llm-wiki reachable from the internet.
  2. The attacker targets the wiki_capture_source MCP tool endpoint via an HTTP or protocol-specific request.
  3. The attacker crafts a request containing a malicious payload injected into the url parameter.
  4. The pi-llm-wiki component processes the request and passes the unvalidated url argument to an underlying system execution function within mcp/index.ts.
  5. The application triggers a shell execution context on the host server.
  6. The injected commands are executed with the privileges of the pi-llm-wiki process.
  7. The attacker establishes persistence or exfiltrates sensitive LLM context and configuration data from the environment.

Impact

Successful exploitation of this vulnerability allows unauthenticated remote attackers to achieve arbitrary code execution. This can lead to total system compromise, data exfiltration, or the poisoning of LLM data pipelines. Given the 9.9 CVSS score, this represents a critical risk to any infrastructure running the affected pi-llm-wiki component.

Recommendation

  • Upgrade the pi-llm-wiki component to version 0.11.8 immediately.
  • Audit logs for unauthorized requests targeting the wiki_capture_source MCP endpoint.
  • Ensure the pi-llm-wiki process runs with the least privilege necessary to minimize potential damage from successful exploitation.

Immediate actions

Upgrade pi-llm-wiki to version 0.11.8

IT Operations 24h

Mitigations

Upgrade pi-llm-wiki to version 0.11.8

immediate IT Operations

CVE-2026-102911