A vulnerability was found in LiuMengxuan04 MiniCode 0.1.0 and classified as critical. Affected by this vulnerability is the function
child_process.spawn of the file mcp.ts. Executing a manipulation can lead to command injection.
This vulnerability is tracked as CVE-2026-16133. The attack can be launched remotely. Moreover, an exploit is present.
The pull request to fix this issue awaits acceptance.