ADB MCP Server is a MCP (Model Context Protocol) server for interacting with Android devices through ADB. In versions 0.1.0 and prior, the MCP Server is written in a way that is vulnerable to command injection vulnerability attacks as part of some of its MCP Server tool definition and implementation. This issue has been patched via commit 041729c.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 25 Sep 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 25 Sep 2025 13:45:00 +0000

Type Values Removed Values Added
Description ADB MCP Server is a MCP (Model Context Protocol) server for interacting with Android devices through ADB. In versions 0.1.0 and prior, the MCP Server is written in a way that is vulnerable to command injection vulnerability attacks as part of some of its MCP Server tool definition and implementation. This issue has been patched via commit 041729c.
Title Command Injection in adb-mcp MCP Server
Weaknesses CWE-77
CWE-78
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-09-25T14:36:27.801Z

Reserved: 2025-09-22T14:34:03.471Z

Link: CVE-2025-59834

cve-icon Vulnrichment

Updated: 2025-09-25T14:36:24.461Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-09-25T14:15:46.357

Modified: 2025-09-26T14:32:53.583

Link: CVE-2025-59834

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.