CVE-2026-7061: A weakness has been identified in Toowiredd chatgpt-mcp-server up to 0.1.0. Affected by this issue is some unknown functionality of the file src/services/docker.service.ts of the component MCP/HTTP...

Added to the CISA Known Exploited Vulnerabilities catalog on 26 Apr 2026. Vendor: AI/ML. Product: chatgpt. CVSS score: 7.3.

A weakness has been identified in Toowiredd chatgpt-mcp-server up to 0.1.0. Affected by this issue is some unknown functionality of the file src/services/docker.service.ts of the component MCP/HTTP. This manipulation causes os command injection. Remote exploitation of the attack is possible. The ...

Required action: Review and patch if applicable to your AI infrastructure.