THREAT OPS › Threat News › [GHSA] GHSA-f5pj-2738-996m (high) — mcp-shell — Security Disabled by Default in Bare-Binary Deploy Path + Shell Interpreter in Secure-Mode Allowlist
[GHSA] GHSA-f5pj-2738-996m (high) — mcp-shell — Security Disabled by Default in Bare-Binary Deploy Path + Shell Interpreter in Secure-Mode Allowlist
GHSA-f5pj-2738-996m Severity: high CVE: CVE-2026-55580
mcp-shell — Security Disabled by Default in Bare-Binary Deploy Path + Shell Interpreter in Secure-Mode Allowlist
mcp-shell` at commit `17ac0eef5c9a5a42b8fb132d3d034973d55a5433` has two issues that together mean neither the default deploy path nor the recommended "secure mode" delivers the restriction they're marketed as providing. Filing the
Indicators of compromise
- 17ac0eef5c9a5a42b8fb132d3d034973d55a5433sha1
- CVE-2026-55580cve
- http://attacker.com/exfil?d=$(caturl
Original source: https://github.com/advisories/GHSA-f5pj-2738-996m