THREAT OPS › Threat News › [NVD] CVE-2026-55582 (HIGH 8.4) — mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, the default security.yaml allows /usr/bin/git, while security.go omits ! from containsShellMetacharacters and containsDangerousShellConstructs and applies no per-executable a
[NVD] CVE-2026-55582 (HIGH 8.4) — mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, the default security.yaml allows /usr/bin/git, while security.go omits ! from containsShellMetacharacters and containsDangerousShellConstructs and applies no per-executable a
CVE-2026-55582 CVSS: 8.4 HIGH Published: 2026-08-25T16:16:55.650
mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, the default security.yaml allows /usr/bin/git, while security.go omits ! from containsShellMetacharacters and containsDangerousShellConstructs and applies no per-executable argument policy. A caller of the shell_exec MCP tool ca
Indicators of compromise
- CVE-2026-55582cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-55582