{"id":"GHSA-j7h9-2jh7-g967","aliases":[],"url":"https://o3.security/vulnerability/GHSA-j7h9-2jh7-g967","summary":"mcp-ssh-tool has file transfer path policy bypass and bearer token comparison hardening","details":"## Summary\n\n`mcp-ssh-tool` has released version `2.1.1` with security hardening for transfer path authorization and HTTP bearer authentication.\n\nThe release addresses:\n\n- insufficient local path policy enforcement in transfer-related filesystem handling\n- incomplete canonicalization and segment-boundary handling for deny-prefix path policy checks\n- non-constant-time HTTP bearer token comparison\n\n## Impact\n\nAffected versions may allow policy bypass in transfer path handling under specific configurations, and may expose a timing side channel in bearer-token comparison for HTTP deployments.\n\n## Patched Version\n\nUpgrade to `mcp-ssh-tool >= 2.1.1`.\n\n```bash\nnpm install -g mcp-ssh-tool@latest\n```\n\n## Workarounds\n\nFor deployments that cannot immediately upgrade:\n\n- avoid exposing HTTP transport beyond loopback\n- use strict filesystem policy configuration\n- avoid granting MCP clients access to sensitive local transfer paths\n- monitor audit logs for unexpected transfer operations\n\n## Credits\n\nReported by `dodge1218`.","published":"2026-05-07T21:45:16Z","modified":"2026-05-21T05:15:08.446595569Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"mcp-ssh-tool","fixedVersion":"2.1.1"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/oaslananka/mcp-ssh-tool/security/advisories/GHSA-j7h9-2jh7-g967"},{"type":"PACKAGE","url":"https://github.com/oaslananka/mcp-ssh-tool"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-05-21T05:15:08.446595569Z"}}