THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-f5pj-2738-996m (high) — mcp-shell — Security Disabled by Default in Bare-Binary Deploy Path + Shell Interpreter in Secure-Mode Allowlist

[GHSA] GHSA-f5pj-2738-996m (high) — mcp-shell — Security Disabled by Default in Bare-Binary Deploy Path + Shell Interpreter in Secure-Mode Allowlist

highgithub_advisoriesPublished 2026-08-25

GHSA-f5pj-2738-996m Severity: high CVE: CVE-2026-55580

mcp-shell — Security Disabled by Default in Bare-Binary Deploy Path + Shell Interpreter in Secure-Mode Allowlist

mcp-shell` at commit `17ac0eef5c9a5a42b8fb132d3d034973d55a5433` has two issues that together mean neither the default deploy path nor the recommended "secure mode" delivers the restriction they're marketed as providing. Filing the

Indicators of compromise

Original source: https://github.com/advisories/GHSA-f5pj-2738-996m