CVE-2026-0757
8.8MCP · Manager for Claude Desktop
A command injection vulnerability in MCP Manager for Claude Desktop allows remote attackers to escape the application sandbox and execute arbitrary code via malicious user interaction.
Executive summary
A critical command injection vulnerability in MCP Manager for Claude Desktop enables sandbox escape and arbitrary code execution, posing a significant risk to user systems.
Vulnerability
This flaw involves improper validation of user-supplied strings within MCP config objects, which leads to OS command injection. An unauthenticated attacker can trigger this by enticing a victim to visit a malicious page or open a malicious file, resulting in code execution at medium integrity.
Business impact
The ability to escape a sandbox and execute arbitrary code represents a severe threat to endpoint integrity and data confidentiality. Successful exploitation could allow an attacker to install persistent malware, exfiltrate sensitive data, or pivot further into the local network. With a CVSS score of 8.8, this vulnerability is considered high severity due to its potential for full system compromise upon successful interaction.
Remediation
Immediate Action: Monitor official vendor communication channels for the release of a security patch and apply it immediately upon availability.
Proactive Monitoring: Review application access logs for unusual command execution patterns or unauthorized attempts to access system-level configuration files.
Compensating Controls: Implement strict endpoint security policies and utilize browser-based security controls to prevent the loading of untrusted or malicious remote content that could trigger the vulnerability.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the high CVSS score and the nature of the sandbox escape, organizations using MCP Manager for Claude Desktop should prioritize this issue. Users must avoid opening suspicious files or interacting with untrusted web content until a vendor-supplied patch is successfully deployed to remediate the command injection flaw.