mcp-ffmpeg-helper Passes a Tool Argument Straight to the Shell (CVE-2026-78430)
NVD·low signal
Published 2026-08-24, the flaw is in handleToolCall in src/tools/handlers.ts of sworddut mcp-ffmpeg-helper 0.1.0, 0.1.1 and 0.2.1, where manipulating the format argument yields OS command injection. NVD scores it 1.9 because it requires local attack access, and the exploit is public. The project was notified through a GitHub issue and did not respond, which is the more useful signal: this is a single-maintainer MCP server with no security process.