mcp-shell 是一个 MCP 服务器,用于安全、可审计且按需地执行 shell 命令。在版本 0.6.0 之前,默认的 security.yaml 允许使用 /usr/bin/git,而 security.go 中缺少对 containsShellMetacharacters 和 containsDangerousShellConstructs 函数的感叹号(!)排除逻辑,并且未实施针对每个可执行文件的参数策略。调用 shell_exec MCP 工具的用户可以提供命令参数 /usr/bin/git -c a
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-55580 | 8.6 HIGH | mcp-shell — Security Disabled by Default in Bare-Binary Deploy Path + Shell Interpreter in |
| CVE-2026-55581 | 8.4 HIGH | mcp-shell: Secure Mode Allowlist Bypass via Default `/bin/bash` Executable |
No comments yet