Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

3 advisories

Loading
mcp-shell — Security Disabled by Default in Bare-Binary Deploy Path + Shell Interpreter in Secure-Mode Allowlist High
CVE-2026-55580 was published for github.com/sonirico/mcp-shell (Go) Aug 25, 2026
sonirico Credited to sonirico
mcp-shell has a Secure Mode Allowlist Bypass via Default `/bin/bash` Executable High
CVE-2026-55581 was published for github.com/sonirico/mcp-shell (Go) Aug 25, 2026
EQSTLab Credited to EQSTLab, useworld, and sonirico useworld useworld
sonirico sonirico
mcp-shell has a Secure Mode Allowlist Bypass via Git Shell Alias High
CVE-2026-55582 was published for github.com/sonirico/mcp-shell (Go) Aug 25, 2026
EQSTLab Credited to EQSTLab and sonirico sonirico sonirico
ProTip! Advisories are also available from the GraphQL API