npm package report

Is yii2-mcp-server safe?

1 known vulnerability, worst severity LOW.

cvss
5.3

how bad it is if exploited, out of 10

epss
1.1%

chance of exploitation in the next 30 days

xyz score
1.1

CyberXYZ composite, out of 10

fig. 01 — GHSA-gc8w-x73w-p4rh, the advisory selected below

// advisories

GHSA-gc8w-x73w-p4rh

LOWCVE-2026-7600

A flaw has been found in ArtMin96 yii2-mcp-server 1.0.2. This impacts the function yiicommandhelp/yiiexecutecommand of the file src/index.ts of the component MCP Interface. Executing a manipulation can lead to os command injection. The attack can be executed remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not r

Affected
<= 1.0.2
Fixed in
not stated
Weakness
CWE-77
Published
2026-05-02
Source
github

GHSANVDMITREreferencereferencereferencereferencereferencereference


// ai model usage

Tracked for PyPI packages. HuggingFace models declare Python dependencies, so npm packages are not covered.


Checked 2026-09-22 at 00:49 UTC. The most recent advisory here was published 2026-05-02. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is yii2-mcp-server safe? npm package security report | CyberXYZ