THREAT OPS › Threat News › [GHSA] GHSA-74hp-mggr-hv58 (high) — mcp-shell has a Secure Mode Allowlist Bypass via Git Shell Alias
[GHSA] GHSA-74hp-mggr-hv58 (high) — mcp-shell has a Secure Mode Allowlist Bypass via Git Shell Alias
GHSA-74hp-mggr-hv58 Severity: high CVE: CVE-2026-55582
mcp-shell has a Secure Mode Allowlist Bypass via Git Shell Alias
### Summary
`mcp-shell`'s "secure mode" is designed to restrict command execution to an allowlist of executables defined in `security.yaml`. The default configuration includes `/usr/bin/git`. The security validator in `security.go` blocks common shell metacharacters (`|&;<>(){
Indicators of compromise
- CVE-2026-55582cve
Original source: https://github.com/advisories/GHSA-74hp-mggr-hv58