CVE-2026-25546 | Coding-Solo godot-mcp up to 0.1.0 Model Context Protocol exec os command injection (ID 64 / EUVD-2026-5327)
A vulnerability classified as critical was found in Coding-Solo godot-mcp up to 0.1.0. Affected by this issue is the function exec of the component Model Context Protocol. The manipulation results in os command injection.
This vulnerability is known as CVE-2026-25546. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is advised.