CRITICAL 9.9 CVE-2026-102911 Published 30 Sept 2026

pi-llm-wiki OS Command Injection Vulnerability

Worried this affects your website?

A flaw has been found in zosmaai pi-llm-wiki up to version 0.11.7. The issue affects an unknown function in the file mcp/index.ts of the wiki_capture_source MCP tool, where manipulating the url argument can lead to OS command injection.

The attack can be executed remotely, and an exploit has been published. Upgrading to version 0.11.8 addresses the issue, with the patch identified as 360867034e79175b45c8e04a98e4ca712bbaca35.

  • Affected versions: up to 0.11.7
  • Fixed version: 0.11.8
  • Attack vector: remote

Reference: CVE-2026-102911 on NVD

← Back to Security News