ZDI-CAN-27810: ZDI-26-023: (0Day) MCP Manager for Claude Desktop execute-command Command Injection Sandbox Escape Vulnerability
This vulnerability allows remote attackers to bypass the sandbox on affected installations of MCP Manager for Claude Desktop. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of MCP config objects. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to escape the sandbox and execute arbitrary code in the context of the current process at medium integrity.
Other sources
This vulnerability allows remote attackers to bypass the sandbox on affected installations of MCP Manager for Claude Desktop. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-0757.
— ZDI
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-27810?
The severity of ZDI-CAN-27810 is critical due to its potential for remote command execution.
How do I fix ZDI-CAN-27810?
To fix ZDI-CAN-27810, update MCP Manager for Claude Desktop to the latest patched version provided by the vendor.
What impact does ZDI-CAN-27810 have on system security?
ZDI-CAN-27810 allows attackers to bypass sandbox restrictions, potentially leading to unauthorized access and execution of harmful commands.
Is user interaction required to exploit ZDI-CAN-27810?
Yes, user interaction is required to exploit the ZDI-CAN-27810 vulnerability effectively.
What are the affected systems by ZDI-CAN-27810?
ZDI-CAN-27810 specifically affects installations of MCP Manager for Claude Desktop.