MEDIUM5.3npmGHSA-xqv9-qr76-hfq2· CVE-2026-5603@elgentos/magento2-dev-mcp vulnerable to command injectionModified: 4/6/2026