Project Subscriptions
No data.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 28 Aug 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 28 Aug 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Maquina-app
Maquina-app rails-mcp-server |
|
| Vendors & Products |
Maquina-app
Maquina-app rails-mcp-server |
Thu, 27 Aug 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The execute_ruby tool is documented as a read-only Ruby sandbox and is enforced by a pattern denylist together with replacements for the process-spawning methods on Kernel. The pseudo-terminal library's spawn entry points are neither in the denylist nor replaced, so a normal tool call could reach them and start a shell, executing commands as the account running the server and outside the guarded methods. The denylist was introduced with the tool in 1.4.0 and never covered those entry points through 1.6.0. Version 1.6.1 restricts the requires the sandbox permits to a data-only list and blocks dynamic dispatch to execution entry points; 2.0.0 removes the tool. | |
| Title | rails-mcp-server 1.4.0 through 1.6.0 OS Command Execution via execute_ruby PTY Escape | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-28T15:59:55.991Z
Reserved: 2026-08-26T16:00:32.686Z
Link: CVE-2026-81097
Updated: 2026-08-27T19:00:40.771Z
Status : Received
Published: 2026-08-27T17:20:52.110
Modified: 2026-08-28T20:20:09.293
Link: CVE-2026-81097
No data.
OpenCVE Enrichment
Updated: 2026-08-28T16:14:30Z