THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-3x77-wg38-92r3 (high) — mcp-shell has a Secure Mode Allowlist Bypass via Default `/bin/bash` Executable

[GHSA] GHSA-3x77-wg38-92r3 (high) — mcp-shell has a Secure Mode Allowlist Bypass via Default `/bin/bash` Executable

medgithub_advisoriesPublished 2026-08-25

GHSA-3x77-wg38-92r3 Severity: high CVE: CVE-2026-55581

mcp-shell has a Secure Mode Allowlist Bypass via Default `/bin/bash` Executable

### Summary

`mcp-shell` ships a default Docker configuration (`security.yaml`) that includes `/bin/bash` in the `allowed_executables` allowlist. The command validator (`security.go`) only checks whether the first token of the supplied command matches an allowed

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-3x77-wg38-92r3