This release includes 1 security fix for security teams reviewing exposed deployments.
Published 25d
MCP Developer Tools
✓ No known CVEs patched
This release patches 1 known CVE
Topics
audit-log
command-whitelist
mcp
model-context-protocol
security
shell
Affected surfaces
rce_ssrf
Summary
AI summarySecurity patch hardens command argument policies against tar, awk, and git execution vulnerabilities
Full changelog
Security patch release for GHSA-gvwf-5g64-3vvw.
- Harden default command argument policy against additional tar command-execution options.
- Harden awk command execution detection.
- Harden git execution-capable config detection.
- Apply default dangerous-argument checks consistently for absolute-path allowlist commands.
Validation:
- make check
- targeted command validator and shell executor tests
Security Fixes
- GHSA-gvwf-5g64-3vvw — Hardened default command argument policy for tar, awk, and git to prevent execution vulnerabilities
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About tumf/mcp-shell-server
A secure shell command execution server implementing the Model Context Protocol (MCP)
Related context
Beta — feedback welcome: [email protected]