CVE-2026-16133: LIUMENGXUAN04 Minicode
Medium severity, CVSS 5.0. EPSS: 1.2% chance of exploitation in the next 30 days.
A flaw has been found in LiuMengxuan04 MiniCode 0.1.0. Affected by this vulnerability is the function child_process.spawn of the file mcp.ts. Executing a manipulation can lead to command injection. The attack can be launched remotely. The attack requires a high level of complexity. The exploitation appears to be difficult. The exploit has been published and may be used. The pull request to fix this issue awaits acceptance.
Affected products
- LIUMENGXUAN04 Minicode: version 0.1.0 only
Published 2026-07-18. Last modified 2026-07-20.