THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-55582 (HIGH 8.4) — mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, the default security.yaml allows /usr/bin/git, while security.go omits ! from containsShellMetacharacters and containsDangerousShellConstructs and applies no per-executable a

[NVD] CVE-2026-55582 (HIGH 8.4) — mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, the default security.yaml allows /usr/bin/git, while security.go omits ! from containsShellMetacharacters and containsDangerousShellConstructs and applies no per-executable a

mednvdPublished 2026-08-25

CVE-2026-55582 CVSS: 8.4 HIGH Published: 2026-08-25T16:16:55.650

mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, the default security.yaml allows /usr/bin/git, while security.go omits ! from containsShellMetacharacters and containsDangerousShellConstructs and applies no per-executable argument policy. A caller of the shell_exec MCP tool ca

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-55582