{"id":"CVE-2026-55580","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-55580","summary":"mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, config.go initializes Security.Enabled to false, and when MCP_SHELL_SEC_CONFIG_FILE…","details":"mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, config.go initializes Security.Enabled to false, and when MCP_SHELL_SEC_CONFIG_FILE is unset, main.go starts the documented bare-binary deployment without a security policy. SecurityValidator.validateCommand in security.go then short-circuits and allows every command supplied to the shell_exec MCP tool, so an LLM connected over stdio can execute unrestricted OS commands as the mcp-shell process user. The README from-source installation and MCP client configuration omit MCP_SHELL_SEC_CONFIG_FILE, making the insecure state the documented default. This issue is fixed in version 0.6.0.","published":"2026-08-25T16:16:55.317","modified":"2026-08-25T16:16:55.317","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"https://github.com/sonirico/mcp-shell/commit/f31377fce6ec31114e5a4398c0e5270552bce09f","label":"sonirico/mcp-shell@f31377f"},"references":[{"type":"WEB","url":"https://github.com/sonirico/mcp-shell/commit/f31377fce6ec31114e5a4398c0e5270552bce09f"},{"type":"WEB","url":"https://github.com/sonirico/mcp-shell/pull/16"},{"type":"WEB","url":"https://github.com/sonirico/mcp-shell/releases/tag/v0.6.0"},{"type":"WEB","url":"https://github.com/sonirico/mcp-shell/security/advisories/GHSA-f5pj-2738-996m"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-25T16:16:55.317"}}