漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
@akoskm/create-mcp-server-stdio has Command Injection in MCP Server due to unsafe `exec` API
Vulnerability Description
@akoskm/create-mcp-server-stdio is an MCP server starter kit that uses the StdioServerTransport. Prior to version 0.0.13, the MCP Server is written in a way that is vulnerable to command injection vulnerability attacks as part of some of its MCP Server tool definition and implementation. The MCP Server exposes the tool `which-app-on-port` which relies on Node.js child process API `exec` which is an unsafe and vulnerable API if concatenated with untrusted user input. Version 0.0.13 contains a fix for the issue.
CVSS Information
N/A
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Vulnerability Title
aws-mcp-server 操作系统命令注入漏洞
Vulnerability Description
aws-mcp-server是Alexei Ledenev个人开发者的一个一种轻量级服务,使AI助手能够通过模型上下文协议(MCP)执行AWS CLI命令(在安全的容器化环境中)。 aws-mcp-server 0.0.13之前版本存在操作系统命令注入漏洞,该漏洞源于命令注入攻击。
CVSS Information
N/A
Vulnerability Type
N/A