CVE-2026-75130
Last modified
CVE-2026-75130 is a critical-severity vulnerability rated 9/10 on the CVSS scale. Context7 through 2.1.2 contains a prompt injection vulnerability that allows attackers to execute malicious instructions in connected AI coding agents by injecting unsanitized content through the Custom AI Instructions feature served via the MCP server. Attackers can poison the custom instructions to exfiltrate credentials from environment files to an attacker-controlled service and perform destructive file deletion on the victim's machine when the agent makes a routine library documentation request.. EPSS estimates a 0.28% chance of exploitation in the next 30 days.
Description
Context7 through 2.1.2 contains a prompt injection vulnerability that allows attackers to execute malicious instructions in connected AI coding agents by injecting unsanitized content through the Custom AI Instructions feature served via the MCP server. Attackers can poison the custom instructions to exfiltrate credentials from environment files to an attacker-controlled service and perform destructive file deletion on the victim's machine when the agent makes a routine library documentation request.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Uptash | Context7 | <= 2.1.2 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-75130?
How severe is CVE-2026-75130?
How do I fix CVE-2026-75130?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-75111Evidently UI fails to properly validate the filename paramet…7.5
- CVE-2026-75112A security issue exists within OTTO® Fleet Manager. The vuln…6.9
- CVE-2026-75114Joomla Extension - yootheme.com - Open redirect in CommentCo…5.1
- CVE-2026-75115Joomla Extension - yootheme.com - Authenticated, privileged …7
- CVE-2026-7512A flaw has been found in UTT HiPER 1200GW up to 2.5.3-1703. …8.8
- CVE-2026-7513A vulnerability has been found in UTT HiPER 1200GW up to 2.5…8.8
- CVE-2026-75140jsoup through 1.23.2, fixed in commit 862ba2f, contains an u…7.5
- CVE-2026-75141FFmpeg before commit acf5d7c contains a heap buffer overflow…7.8
- CVE-2026-75142FFmpeg before commit 9d786e4 contains a stack buffer overflo…7.8
- CVE-2026-75143FFmpeg before commit 1c10bcc contains a heap buffer overflow…9.8
- CVE-2026-75144FFmpeg before commit 1cdeb3c contains a heap buffer overflow…7.8
- CVE-2026-75145FFmpeg before commit b4c199c contains an incorrect integer n…5.8
Are you affected by CVE-2026-75130?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
