{"ok":true,"trend":{"id":442128,"platform":"mastodon","region":"global","key":"cve-2026-102911: zosmaai pi-llm-wiki (v0.11.0 – 0.11.7) suffers critical os command injection in mcp/index.ts. public ex","title":"CVE-2026-102911: zosmaai pi-llm-wiki (v0.11.0 – 0.11.7) suffers CRITICAL OS command injection in mcp/index.ts. Public ex","url":"https://infosec.exchange/@offseq/117358108618797914","first_seen":"2026-09-30T04:41:05.902259Z","last_seen":"2026-09-30T04:41:05.902259Z","last_rank":11,"peak_rank":11,"last_volume":1,"peak_volume":1,"seen_count":1,"score":0.78734375,"category_hint":"cybersecurity","section":"technology","category":"cybersecurity","summary":"A critical vulnerability, CVE-2026-102911, has been disclosed in zosmaai's pi-llm-wiki software, versions 0.11.0 through 0.11.7. The flaw is an OS command injection in mcp/index.ts that could allow remote code execution, and a public exploit is already available. Users are urged to upgrade to version 0.11.8 immediately. Security researchers are sharing the advisory and stressing the urgency given the public exploit code.","why":"A critical remotely exploitable flaw with a public exploit is circulating, prompting urgent upgrade warnings in the security community.","tone":"negative","entities":["zosmaai","pi-llm-wiki","CVE-2026-102911","Offseq"],"summarized_at":"2026-09-30T04:43:14.786034Z","meta":{"tag":"infosec","via":"scan","kind":"status","lang":"en","instance":"mastodon.social","tag_uses":1183},"nw":null,"promo":null,"kind":null,"importance":null,"hidden":false,"hide_reason":null,"judged_at":null,"title_en":"Critical command injection flaw disclosed in pi-llm-wiki","section_name":"Technology","category_name":"Cybersecurity","timeline":[{"captured_at":"2026-09-30T04:41:05.902259Z","rank":11,"volume":1}],"posts":[{"platform":"mastodon","url":"https://infosec.exchange/@offseq/117358108618797914","author":"offseq@infosec.exchange","title":null,"snippet":"CVE-2026-102911: zosmaai pi-llm-wiki (v0.11.0 – 0.11.7) suffers CRITICAL OS command injection in mcp/index.ts. Public exploit available — remote code execution possible. Upgrade to 0.11.8 ASAP. https:// radar.offseq.com/threat/cve-20…","posted_at":"2026-09-30T04:30:24Z","likes":1}],"elsewhere":[],"window":"7d"}}