Description

5ire is a cross-platform desktop artificial intelligence assistant and model context protocol client. Prior to version 0.15.3, an unsafe option parsing vulnerability in the ECharts Markdown plugin allows any user able to submit ECharts code blocks to execute arbitrary JavaScript code in the renderer context. This can lead to Remote Code Execution (RCE) in environments where privileged APIs (such as Electron’s electron.mcp) are exposed, resulting in full compromise of the host system. Version 0.15.3 patches the issue.

INFO

Published Date :

2026-01-21T21:06:58.205Z

Last Modified :

2026-01-21T21:26:07.121Z

Source :

GitHub_M
AFFECTED PRODUCTS

The following products are affected by CVE-2026-22793 vulnerability.

Vendors Products
5ire
  • 5ire
Nanbingxyz
  • 5ire
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2026-22793.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact