Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2534 articles · 111766 vulns · 38/41 feeds (7d)
← Back to list
EST
PRE-CVE

terminal-controller-mcp Trivially Bypassable Command Blocklist Allows Unrestricted RCE

56% confidence

Description

The terminal-controller-mcp software contains a command blocklist that is trivially bypassable, enabling unrestricted remote code execution (RCE) via crafted input.

Affected Products

VendorProductVersions
—terminal-controller-mcp—

Related News (1 articles)

Tier C
oss-security3h ago
Re: [CVE REQUEST] terminal-controller-mcp: trivially bypassable command blocklist enables unrestricted RCE (CVSS 10.0)
→ No new info (linked only)
CISA KEV❌ No
Actively exploited❌ No
PublishedApr 19, 2026
Last enriched3h ago
Tags
rceblocklist-bypass
Trending Score30
Source articles1
Independent1
Info Completeness4/14
Missing: cve_id, vendor, versions, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Pin to Dashboard

Verification

State: reported
Confidence: 56%

Vulnerability Timeline

CVE Published
Apr 19, 2026
Discovered by ZDM
Apr 19, 2026