All 3 CVE vulnerabilities found in mcp-shell, with AI-generated Chinese analysis, references, and POCs.
Vendor: sonirico
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-55580 | mcp-shell — Security Disabled by Default in Bare-Binary Deploy Path + Shell Interpreter in Secure-Mode Allowlist CWE-78 | 8.6 | High | 2026-08-25 |
| CVE-2026-55581 | mcp-shell: Secure Mode Allowlist Bypass via Default `/bin/bash` Executable CWE-78 | 8.4 | High | 2026-08-25 |
| CVE-2026-55582 | mcp-shell: Secure Mode Allowlist Bypass via Git Shell Alias CWE-78 | 8.4 | High | 2026-08-25 |
All 3 known CVE vulnerabilities affecting mcp-shell with full Chinese analysis, references, and POCs where available.