command-executor MCP Server是Maki个人开发者的一款预批准命令的安全执行工具。 command-executor MCP Server 0.1.0及之前版本存在命令注入漏洞,该漏洞源于MCP Interface组件中src/index.ts文件的execute_command函数操作不当,可能导致OS命令注入。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Sunwood-ai-labs | command-executor-mcp-server | 0.1.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Sunwood-ai-labs | command-executor-mcp-server | 0.1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
VULNERABLE: OS command injection confirmed - read /etc/shadow via "ls ; cat /etc/shadow" VULNERABLE: OS command injection confirmed - read /etc/shadow via "ls ; cat /etc/shadow"
No comments yet