This release includes 1 security fix for security teams reviewing exposed deployments.
Published 2h
MCP Developer Tools
✓ No known CVEs patched
This release patches 1 known CVE
Topics
audit-log
command-whitelist
mcp
model-context-protocol
security
shell
Affected surfaces
rce_ssrf
Summary
AI summaryReject sed, GNU find output actions, and AWK external file access / script execution.
Full changelog
Security
- Reject
sed, including embedded command execution and file access scripts. - Reject GNU
findfile-output actions (-fprintf,-fprint,-fprint0, and-fls). - Reject AWK external file access and script-file execution.
Fixes GHSA-88qq-fvcm-92qq.
PyPI: https://pypi.org/project/mcp-shell-server/1.1.3/
Security Fixes
- GHSA-88qq-fvcm-92qq — Reject sed, GNU find file-output actions (-fprintf, -fprint, -fprint0, -fls), and AWK external file access / script execution.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About tumf/mcp-shell-server
A secure shell command execution server implementing the Model Context Protocol (MCP)
Related context
Beta — feedback welcome: [email protected]