Sploitus

CVE-2026-22793

No indexed exploits for CVE-2026-22793 yet

5ire is a cross-platform desktop artificial intelligence assistant and model context protocol client. Prior to version 0.15.3, an unsafe option parsing vulnerability in the ECharts Markdown plugin allows any user able to submit ECharts code blocks to execute arbitrary JavaScript code in the renderer context. This can lead to Remote Code Execution (RCE) in environments where privileged APIs (such as Electron’s electron.mcp) are exposed, resulting in full compromise of the host system. Version 0.15.3 patches the issue.

Affected products
5Ire, Echarts Markdown Plugin
5ire
< 0.15.3
Fix
Available
CVSS 3.1
9.6 CRITICAL
EPSS
0.6% (46th percentile)
Weakness
CWE-94
NVD status
Analyzed
Published
2026-01-21
CVE-2026-22793 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-22793 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-22793 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.