{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-102911/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:zosmaai:pi-llm-wiki:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.9,"id":"CVE-2026-102911"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["pi-llm-wiki (\u003c= 0.11.7)"],"_cs_severities":["critical"],"_cs_tags":["remote-code-execution","cve-2026-102911","web-security"],"_cs_type":"advisory","_cs_vendors":["zosmaai"],"content_html":"\u003cp\u003eThe zosmaai pi-llm-wiki project contains a critical OS command injection vulnerability, tracked as CVE-2026-102911, impacting all versions up to and including 0.11.7. The vulnerability resides within the wiki_capture_source functionality implemented in mcp/index.ts. By supplying a maliciously crafted string to the url argument, an attacker can escape the intended input boundaries and execute arbitrary operating system commands on the host machine. Given that the pi-llm-wiki tool is designed to interface with LLM pipelines, it is frequently exposed to external inputs, significantly increasing the risk of exploitation. Publicly available exploit code exists, heightening the immediate threat to organizations running this component in reachable environments. Organizations should upgrade to version 0.11.8 immediately to apply the patch identified as 360867034e79175b45c8e04a98e4ca712bbaca35.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe attacker identifies an instance of zosmaai pi-llm-wiki reachable from the internet.\u003c/li\u003e\n\u003cli\u003eThe attacker targets the wiki_capture_source MCP tool endpoint via an HTTP or protocol-specific request.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a request containing a malicious payload injected into the url parameter.\u003c/li\u003e\n\u003cli\u003eThe pi-llm-wiki component processes the request and passes the unvalidated url argument to an underlying system execution function within mcp/index.ts.\u003c/li\u003e\n\u003cli\u003eThe application triggers a shell execution context on the host server.\u003c/li\u003e\n\u003cli\u003eThe injected commands are executed with the privileges of the pi-llm-wiki process.\u003c/li\u003e\n\u003cli\u003eThe attacker establishes persistence or exfiltrates sensitive LLM context and configuration data from the environment.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows unauthenticated remote attackers to achieve arbitrary code execution. This can lead to total system compromise, data exfiltration, or the poisoning of LLM data pipelines. Given the 9.9 CVSS score, this represents a critical risk to any infrastructure running the affected pi-llm-wiki component.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the pi-llm-wiki component to version 0.11.8 immediately.\u003c/li\u003e\n\u003cli\u003eAudit logs for unauthorized requests targeting the wiki_capture_source MCP endpoint.\u003c/li\u003e\n\u003cli\u003eEnsure the pi-llm-wiki process runs with the least privilege necessary to minimize potential damage from successful exploitation.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-30T04:31:17Z","date_published":"2026-09-30T04:31:17Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-102911/","summary":"An OS command injection vulnerability in the wiki_capture_source MCP tool of zosmaai pi-llm-wiki versions up to 0.11.7 allows remote unauthenticated attackers to execute arbitrary commands via the url argument.","title":"Remote Code Execution in zosmaai pi-llm-wiki","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-102911/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-102911","version":"https://jsonfeed.org/version/1.1"}