ForgeCode Untrusted .mcp.json Auto-Execution Leading to Arbitrary Code Execution
highAgentCode ExecutionForgeCode, an AI pair-programming CLI, automatically parses and executes MCP server configurations from a repository's .mcp.json file without any user confirmation. A malicious or compromised repository can embed arbitrary OS commands in this file, achieving code execution with the developer's privileges the moment they run forge inside the cloned repo. This turns routine repository evaluation into a reliable initial-access vector for supply-chain attacks against developers.
Updated Jul 19, 2026 · CVSS 7.8