Skip to content

tumf/mcp-shell-server

v1.1.3 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 2h MCP Developer Tools
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

audit-log command-whitelist mcp model-context-protocol security shell

Affected surfaces

rce_ssrf

Summary

AI summary

Reject sed, GNU find output actions, and AWK external file access / script execution.

Full changelog

Security

  • Reject sed, including embedded command execution and file access scripts.
  • Reject GNU find file-output actions (-fprintf, -fprint, -fprint0, and -fls).
  • Reject AWK external file access and script-file execution.

Fixes GHSA-88qq-fvcm-92qq.

PyPI: https://pypi.org/project/mcp-shell-server/1.1.3/

Security Fixes

  • GHSA-88qq-fvcm-92qq — Reject sed, GNU find file-output actions (-fprintf, -fprint, -fprint0, -fls), and AWK external file access / script execution.

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track tumf/mcp-shell-server

Get notified when new releases ship.

Sign up free

About tumf/mcp-shell-server

A secure shell command execution server implementing the Model Context Protocol (MCP)

All releases →

Beta — feedback welcome: [email protected]