← Back to browse · API

CVE-2026-26015

Severity
CRITICAL
CVSS
10.0
EPSS
0.01168
Risk score
40.41
CISA KEV
No
PoC
No
Published
2026-04-29
Modified
2026-05-06
First seen
2026-08-07
Aliases
EUVD-2026-26258
Products
arc53:DocsGPT 0.15.0, < 0.16.0
Sources
euvd EUVD-2026-26258

Description

DocsGPT is a GPT-powered chat for documentation. From version 0.15.0 to before version 0.16.0, an attacker accessing both the official DocsGPT website or any local and public deployment, can craft a malicious payload bypassing the "MCP test" behavior to achieve arbitrary remote code execution (RCE). This issue has been patched in version 0.16.0.

References