CVE-2026-55580: mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, config.go initializes Security.Enabled to false, and when MCP_SHELL_SEC_CONFIG_FILE is unse...
Added to the CISA Known Exploited Vulnerabilities catalog on 25 Aug 2026. Vendor: AI/ML. Product: LLM.
mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, config.go initializes Security.Enabled to false, and when MCP_SHELL_SEC_CONFIG_FILE is unset, main.go starts the documented bare-binary deployment without a security policy. SecurityValidator...
Required action: Review and patch if applicable to your AI infrastructure.