CVE-2026-55580
- EPSS 0.15%
- Veröffentlicht 25.08.2026 15:42:36
- Zuletzt bearbeitet 09.09.2026 21:07:31
mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, config.go initializes Security.Enabled to false, and when MCP_SHELL_SEC_CONFIG_FILE is unset, main.go starts the documented bare-binary deployme...
CVE-2026-55581
- EPSS 0.34%
- Veröffentlicht 25.08.2026 15:40:10
- Zuletzt bearbeitet 09.09.2026 21:07:31
mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, the default Docker security.yaml includes /bin/bash in allowed_executables, while security.go validates only the first token and checkBlockedPat...
CVE-2026-55582
- EPSS 0.19%
- Veröffentlicht 25.08.2026 15:37:43
- Zuletzt bearbeitet 09.09.2026 21:07:31
mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, the default security.yaml allows /usr/bin/git, while security.go omits ! from containsShellMetacharacters and containsDangerousShellConstructs a...
CVE-2025-61489
- EPSS 0.88%
- Veröffentlicht 07.01.2026 00:00:00
- Zuletzt bearbeitet 29.01.2026 01:13:50
A command injection vulnerability in the shell_exec function of sonirico mcp-shell v0.3.1 allows attackers to execute arbitrary commands via supplying a crafted command string.