HarborGuard / CVE
Back to search
CRITICALCVE-2026-23523Published Modified CNA GitHub_M

CVE-2026-23523: Dive allows One-click Remote Code Execution through Deep Links for MCP Install

Dive is an open-source MCP Host Desktop Application that enables integration with function-calling LLMs. Prior to 0.13.0, crafted deeplink can install an attacker-controlled MCP server configuration without sufficient user confirmation and can lead to arbitrary local command execution on the victim’s machine. This vulnerability is fixed in 0.13.0.

Metrics

CVSS v3.1
9.7
Severity
CRITICAL
Fixed in
Affected Products
1
Affected packages
  • OpenAgentPlatform / Dive
    < 0.13.0
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H