Dive is an open-source MCP Host Desktop Application that enables integration with function-calling LLMs. Prior to 0.13.0, crafted deeplink can install an attacker-controlled MCP server configuration without sufficient user confirmation and can lead to arbitrary local command execution on the victim’s machine. This vulnerability is fixed in 0.13.0.
History

Fri, 16 Jan 2026 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 16 Jan 2026 16:45:00 +0000

Type Values Removed Values Added
Description Dive is an open-source MCP Host Desktop Application that enables integration with function-calling LLMs. Prior to 0.13.0, crafted deeplink can install an attacker-controlled MCP server configuration without sufficient user confirmation and can lead to arbitrary local command execution on the victim’s machine. This vulnerability is fixed in 0.13.0.
Title Dive allows One-click Remote Code Execution through Deep Links for MCP Install
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 9.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-01-16T16:47:34.560Z

Reserved: 2026-01-13T18:22:43.980Z

Link: CVE-2026-23523

cve-icon Vulnrichment

Updated: 2026-01-16T16:47:26.604Z

cve-icon NVD

Status : Received

Published: 2026-01-16T17:15:54.480

Modified: 2026-01-16T17:15:54.480

Link: CVE-2026-23523

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.