VDB

GCVE-110-PYPI-2026-013716

GCVE-110-PYPI-2026-013716
Advisory Published
Vulnetix · Advisory published July 5, 2026
[IOC-STIX-MATCH] Malicious domain agentclientprotocol.com — referenced in agent-client-protocol/setup.py — matched: description="The _meta property is reserved by ACP to allow clients and agents to attach additional\nmetadata to their interactions. Implementations MUST NOT make assumptions about values at\nthese keys.\n\nSee protocol docs: [Extensibility](https://agentclientprotocol.com/protocol/exten

Weaknesses (CWE)

CWE-506Embedded Malicious CodeCWE-94Improper Control of Generation of Code ('Code Injection')

Affected Products

VendorProductVersionsPlatforms
pypiagent-client-protocol* (affected)

References

advisory
web

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›