Sonirico

Mcp-shell

4 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.15%
  • Veröffentlicht 25.08.2026 15:42:36
  • Zuletzt bearbeitet 09.09.2026 21:07:31

mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, config.go initializes Security.Enabled to false, and when MCP_SHELL_SEC_CONFIG_FILE is unset, main.go starts the documented bare-binary deployme...

  • EPSS 0.34%
  • Veröffentlicht 25.08.2026 15:40:10
  • Zuletzt bearbeitet 09.09.2026 21:07:31

mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, the default Docker security.yaml includes /bin/bash in allowed_executables, while security.go validates only the first token and checkBlockedPat...

  • EPSS 0.19%
  • Veröffentlicht 25.08.2026 15:37:43
  • Zuletzt bearbeitet 09.09.2026 21:07:31

mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, the default security.yaml allows /usr/bin/git, while security.go omits ! from containsShellMetacharacters and containsDangerousShellConstructs a...

Exploit
  • EPSS 0.88%
  • Veröffentlicht 07.01.2026 00:00:00
  • Zuletzt bearbeitet 29.01.2026 01:13:50

A command injection vulnerability in the shell_exec function of sonirico mcp-shell v0.3.1 allows attackers to execute arbitrary commands via supplying a crafted command string.