← Back to browse · API

CVE-2026-23523

Severity
CRITICAL
CVSS
9.7
EPSS
0.06299
Risk score
41.0
CISA KEV
No
PoC
No
Published
2026-01-16
Modified
2026-01-16
First seen
2026-08-07
Aliases
EUVD-2026-3125
Products
OpenAgentPlatform:Dive < 0.13.0
Sources
euvd EUVD-2026-3125

Description

Dive is an open-source MCP Host Desktop Application that enables integration with function-calling LLMs. Prior to 0.13.0, crafted deeplink can install an attacker-controlled MCP server configuration without sufficient user confirmation and can lead to arbitrary local command execution on the victim’s machine. This vulnerability is fixed in 0.13.0.

References