CVE-2026-26015: ARC53 Docsgpt
Critical severity, CVSS 9.8. EPSS: 1.5% chance of exploitation in the next 30 days.
DocsGPT is a GPT-powered chat for documentation. From version 0.15.0 to before version 0.16.0, an attacker accessing both the official DocsGPT website or any local and public deployment, can craft a malicious payload bypassing the "MCP test" behavior to achieve arbitrary remote code execution (RCE). This issue has been patched in version 0.16.0.
Affected products
- ARC53 Docsgpt: version 0.15.0 only
Published 2026-04-29. Last modified 2026-06-17.