The specific flaw exists within the shortcutName parameter. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the service account. Was ZDI-CAN-27910.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.zerodayinitiative.com/advisories/ZDI-26-024/ |
|
Fri, 23 Jan 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 23 Jan 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mcp-server-siri-shortcuts
Mcp-server-siri-shortcuts mcp-server-siri-shortcuts |
|
| Vendors & Products |
Mcp-server-siri-shortcuts
Mcp-server-siri-shortcuts mcp-server-siri-shortcuts |
Fri, 23 Jan 2026 04:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | mcp-server-siri-shortcuts shortcutName Command Injection Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of mcp-server-siri-shortcuts. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the shortcutName parameter. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the service account. Was ZDI-CAN-27910. | |
| Title | mcp-server-siri-shortcuts shortcutName Command Injection Privilege Escalation Vulnerability | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: zdi
Published:
Updated: 2026-01-23T19:31:34.636Z
Reserved: 2026-01-08T22:49:35.684Z
Link: CVE-2026-0758
Updated: 2026-01-23T19:31:29.945Z
Status : Deferred
Published: 2026-01-23T04:16:02.433
Modified: 2026-04-15T00:35:42.020
Link: CVE-2026-0758
No data.
OpenCVE Enrichment
Updated: 2026-04-18T03:30:25Z