ADB MCP Server is a MCP (Model Context Protocol) server for interacting with Android devices through ADB. In versions 0.1.0 and prior, the MCP Server is written in a way that is vulnerable to command injection vulnerability attacks as part of some of its MCP Server tool definition and implementation. This issue has been patched via commit 041729c.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-31042 Command Injection in adb-mcp MCP Server
Github GHSA Github GHSA GHSA-54j7-grvr-9xwg Command Injection in adb-mcp MCP Server
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 14 Oct 2025 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Srmorete
Srmorete adb Mcp Server
CPEs cpe:2.3:a:srmorete:adb_mcp_server:*:*:*:*:*:node.js:*:*
Vendors & Products Srmorete
Srmorete adb Mcp Server

Mon, 29 Sep 2025 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Adb Mcp Project
Adb Mcp Project adb Mcp
Google
Google android
Vendors & Products Adb Mcp Project
Adb Mcp Project adb Mcp
Google
Google android

Thu, 25 Sep 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 25 Sep 2025 13:45:00 +0000

Type Values Removed Values Added
Description ADB MCP Server is a MCP (Model Context Protocol) server for interacting with Android devices through ADB. In versions 0.1.0 and prior, the MCP Server is written in a way that is vulnerable to command injection vulnerability attacks as part of some of its MCP Server tool definition and implementation. This issue has been patched via commit 041729c.
Title Command Injection in adb-mcp MCP Server
Weaknesses CWE-77
CWE-78
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-09-25T14:36:27.801Z

Reserved: 2025-09-22T14:34:03.471Z

Link: CVE-2025-59834

cve-icon Vulnrichment

Updated: 2025-09-25T14:36:24.461Z

cve-icon NVD

Status : Analyzed

Published: 2025-09-25T14:15:46.357

Modified: 2025-10-14T20:05:46.243

Link: CVE-2025-59834

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-09-29T09:31:34Z