CVE-2026-22793
5ire is a cross-platform desktop artificial intelligence assistant and model context protocol client. Prior to version 0.15.3, an unsafe option parsing vulnerability in the ECharts Markdown plugin allows any user able to submit ECharts code blocks to execute arbitrary JavaScript code in the renderer context. This can lead to Remote Code Execution (RCE) in environments where privileged APIs (such as Electron’s electron.mcp) are exposed, resulting in full compromise of the host system. Version 0.15.3 patches the issue.
- Affected products
- 5Ire, Echarts Markdown Plugin
- 5ire
- < 0.15.3
- Fix
- Available
- CVSS 3.1
- 9.6 CRITICAL
- EPSS
- 0.6% (46th percentile)
- Weakness
- CWE-94
- NVD status
- Analyzed
- Published
- 2026-01-21
No indexed exploits for CVE-2026-22793 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2026-22793 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.