GHSA-wfpw-4v5h-6h32CriticalCVSS 8.1

cli-mcp-server 0.2.5 contains a command allowlist bypass vulnerability in the...

Published
September 4, 2026
Last Modified
September 4, 2026

🔗 CVE IDs covered (1)

📋 Description

cli-mcp-server 0.2.5 contains a command allowlist bypass vulnerability in the _validate_command_with_operators function when ALLOW_SHELL_OPERATORS is enabled. Attackers can use shell command substitution syntax like $(...) or backticks to execute non-allowlisted commands that bypass the ALLOWED_COMMANDS validation check.

🔗 References (6)