Vulnerability Description
mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, the default Docker security.yaml includes /bin/bash in allowed_executables, while security.go validates only the first token and checkBlockedPatternsAndCommands does not reject the shell command-mode flag -c. A caller of the shell_exec MCP tool can provide the command argument `/bin/bash -c <arbitrary-command>`, which passes validation and reaches executor.go, where parseCommand and exec.CommandContext execute the arbitrary command as mcpuser outside the intended allowlist. This issue is fixed in version 0.6.0.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/sonirico/mcp-shell/commit/f31377fce6ec31114e5a4398c0e5270552b
- https://github.com/sonirico/mcp-shell/pull/16
- https://github.com/sonirico/mcp-shell/releases/tag/v0.6.0
- https://github.com/sonirico/mcp-shell/security/advisories/GHSA-3x77-wg38-92r3
- https://github.com/sonirico/mcp-shell/security/advisories/GHSA-3x77-wg38-92r3
FAQ
What is CVE-2026-55581?
CVE-2026-55581 is a vulnerability with a CVSS score of 8.4 (HIGH). mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, the default Docker security.yaml includes /bin/bash in allowed_executables, while security.go ...
How severe is CVE-2026-55581?
CVE-2026-55581 has been rated HIGH with a CVSS base score of 8.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-55581?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.