github.com/sonirico/mcp-shell
Go3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/sonirico/mcp-shellpage 1 of 1
- CVE-2026-55580HIGHCVSS 8.6EG 8.6✓ Fixed in 0.6.02026-08-25
mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, config.go initializes Security.Enabled to false, and when MCP_SHELL_SEC_CONFIG_FILE is unset, main.go starts the documented bare-bina…
- CVE-2026-55581HIGHCVSS 8.4EG 8.4✓ Fixed in 0.6.02026-08-25
mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, the default Docker security.yaml includes /bin/bash in allowed_executables, while security.go validates only the first token and chec…
- CVE-2026-55582HIGHCVSS 8.4EG 8.4✓ Fixed in 0.6.02026-08-25
mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, the default security.yaml allows /usr/bin/git, while security.go omits ! from containsShellMetacharacters and containsDangerousShellC…
Check whether github.com/sonirico/mcp-shell is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/sonirico/mcp-shell CVEs against the assets you own.
Start Free Scan →