← Back to CVE search

CVE-2026-57860

ForgeCode

Description

ForgeCode (tailcallhq/forgecode), an AI pair-programming CLI, automatically loads and executes the MCP servers defined in a repository-s .mcp.json file on startup without user confirmation. A malicious repository can supply a crafted .mcp.json whose mcpServers entries specify arbitrary command and args values (for example, command: bash with args: [--c-, -touch /tmp/pwned-]). When a user runs the forge CLI inside a cloned untrusted repository, the specified commands are spawned with the invoking user-s privileges, resulting in arbitrary code execution. This provides a reliable initial-access and persistence primitive against developers who evaluate untrusted repositories with ForgeCode.

CVSS 7.8EPSS 0.134%Risk 0.79
View source
Published
2026-07-17 17:17:16
Affected versions
unknown
Type
Web application
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H