CVE-2026-105797 - SimpleChat: Command injection via authorization-gate ordering flaw (arbitrary process spawn through MCP stdio transport)
CVE ID :CVE-2026-105797 Published : Oct. 6, 2026, 2:23 p.m. | 1 hour, 5 minutes ago Description :SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions. In versions 0.261.003 and 0.261.027, an authorization ordering flaw in...