CVE-2026-26029 | akutishevsky sf-mcp-server up to 1.0.2 child_process.exec os command injection
A vulnerability has been found in akutishevsky sf-mcp-server up to 1.0.2 and classified as critical. This issue affects the function child_process.exec. The manipulation leads to os command injection.
This vulnerability is referenced as CVE-2026-26029. Remote exploitation of the attack is possible. No exploit is available.
The affected component should be upgraded.