CVE Explorer
CVE-2026-23523
Dive is an open-source MCP Host Desktop Application that enables integration with function-calling LLMs. Prior to 0.13.0, crafted deeplink can install an attacker-controlled MCP server configuration without sufficient user confirmation and can lead to arbitrary local command execution on the victim’s machine. This vulnerability is fixed in 0.13.0.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"Dive","vendor":"OpenAgentPlatform","versions":[{"status":"affected","version":"< 0.13.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:ec72c28d6929f24e377f63377ad073a686661749b9560f75ca9ee4d1ea2a87aa · sha256:4306268c142e1f39… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.7,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"CHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:ec72c28d6929f24e377f63377ad073a686661749b9560f75ca9ee4d1ea2a87aa · sha256:4306268c142e1f39… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-94","description":"CWE-94: Improper Control of Generation of Code ('Code Injection')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:ec72c28d6929f24e377f63377ad073a686661749b9560f75ca9ee4d1ea2a87aa · sha256:4306268c142e1f39… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"https://github.com/OpenAgentPlatform/Dive/commit/a5162ac9eff366d8ea1215b8a47139a81a55a779","tags":["x_refsource_MISC"],"url":"https://github.com/OpenAgentPlatform/Dive/commit/a5162ac9eff366d8ea1215b8a47139a81a55a779"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:ec72c28d6929f24e377f63377ad073a686661749b9560f75ca9ee4d1ea2a87aa · sha256:4306268c142e1f39… · /containers/cna/references/1
{"name":"https://github.com/OpenAgentPlatform/Dive/security/advisories/GHSA-pjj5-f3wm-f9m8","tags":["x_refsource_CONFIRM"],"url":"https://github.com/OpenAgentPlatform/Dive/security/advisories/GHSA-pjj5-f3wm-f9m8"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:ec72c28d6929f24e377f63377ad073a686661749b9560f75ca9ee4d1ea2a87aa · sha256:4306268c142e1f39… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.