CVE-2026-55582
8.4sonirico · mcp-shell
The mcp-shell server contains an OS command injection vulnerability, which may allow an attacker to execute arbitrary commands on the underlying system.
Executive summary
An OS command injection vulnerability in sonirico mcp-shell versions prior to 0.6.0 presents a significant risk of unauthorized command execution.
Vulnerability
This vulnerability is an OS command injection flaw (CWE-78) resulting from improper neutralization of special elements. It allows an unauthenticated attacker to manipulate inputs to execute unintended shell commands.
Business impact
Successful exploitation allows an attacker to gain control over the host system by executing arbitrary commands. A CVSS score of 8.4 highlights the critical nature of this flaw, which could lead to data exfiltration, service disruption, or further lateral movement within the network.
Remediation
Immediate Action: Update to mcp-shell version 0.6.0 or later immediately to remediate the command injection vector.
Proactive Monitoring: Monitor system logs for suspicious command-line activity or unauthorized administrative actions.
Compensating Controls: Implement strict firewall rules to isolate the mcp-shell service and restrict access only to trusted internal endpoints.
Exploitation status
Public Exploit Available: No (unknown)
Analyst recommendation
The severity of this command injection vulnerability necessitates an immediate update to version 0.6.0. Organizations must prioritize this remediation to prevent unauthorized system access and maintain the integrity of their shell-based operations.