ZDI-26-023: (0Day) MCP Manager for Claude Desktop execute-command Command Injection Sandbox Escape Vulnerability
This vulnerability allows remote attackers to bypass the sandbox on affected installations of MCP Manager for Claude Desktop. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of MCP config objects. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to escape the sandbox and execute arbitrary code in the context of the current process at medium integrity.
Other sources
This vulnerability allows remote attackers to bypass the sandbox on affected installations of MCP Manager for Claude Desktop. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-0757.
— ZDI
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-023?
The severity of ZDI-26-023 is critical due to its potential for remote command execution.
How do I fix ZDI-26-023?
To fix ZDI-26-023, update your MCP Manager for Claude Desktop to the latest version provided by the vendor.
Who is affected by ZDI-26-023?
Users of MCP Manager for Claude Desktop are affected by ZDI-26-023.
Is user interaction required to exploit ZDI-26-023?
Yes, user interaction is required to exploit the ZDI-26-023 vulnerability.
What does ZDI-26-023 allow attackers to do?
ZDI-26-023 allows remote attackers to bypass the sandbox on affected installations of MCP Manager for Claude Desktop.