A critical OS command injection flaw in the wiki_capture_source MCP tool of zosmaai pi-llm-wiki (versions up to 0.11.7) can be exploited remotely through the url argument. A public exploit has been published.
What Is It
CVE-2026-102911 is an OS command injection vulnerability (CWE-77, CWE-78) in zosmaai pi-llm-wiki. It is in an unspecified function in mcp/index.ts, which is part of the wiki_capture_source MCP tool. An attacker who manipulates the url argument can run operating system commands.
The CNA (VulDB) published the record on 2026-09-30. NVD lists its status as "Received."
Why It Matters
- CVSS 3.1: 9.9 CRITICAL (
AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H) - CVSS 4.0: 8.6 HIGH, with exploit maturity rated Proof-of-Concept
- CVSS 2.0: 9.0
The attack works over the network, has low complexity and needs no user interaction. The attacker only needs low privileges. Under CVSS 3.1 the scope is Changed, and the confidentiality, integrity and availability impacts are all High. According to the advisory, "the exploit has been published and may be used."
This CVE is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, so KEV does not confirm any active exploitation.
What's Vulnerable
- Vendor: zosmaai
- Product: pi-llm-wiki
- Component:
wiki_capture_sourceMCP tool (mcp/index.ts) - Affected versions: up to and including 0.11.7. The advisory does not name a lower bound.
- Unaffected: 0.11.8
- CPE:
cpe:2.3:a:zosmaai:pi-llm-wiki:*:*:*:*:*:*:*:*
Patch Status
A fix is available. The advisory says upgrading to version 0.11.8 fixes the issue, and the patch is commit 360867034e79175b45c8e04a98e4ca712bbaca35. The project's references include an issue (#185), a pull request (#186) and the v0.11.8 release. The advisory recommends upgrading the affected component.
This CVE has no CISA KEV entry, so no federal remediation deadline or required action applies.