Impact
The weakness sits in the ssh_exec handler of the ssh‑mcp‑server, where manipulations of the host or username parameters can lead to the injection of arbitrary shell commands. The flaw is classified as command injection (CWE‑74). The maintainers note that the actual existence of the vulnerability is in question; they acknowledge that the code may or may not actually allow injection, and the product is intended for local use where callers already possess execution capability. Because of this uncertainty, the real risk may be lower than a typical operational scenario would suggest.
Affected Systems
Any release of Kino‑Kafkaesque’s ssh‑mcp‑server up to commit 8ebbbb99b26f80ff6162fe00957c6dec73fbc5a5 may contain the flaw. The project follows a rolling release model, so newer commits may contain a fix, but no specific version numbers are available for the affected state.
Risk and Exploitability
The CVSS score of 4.8 indicates a moderate risk profile. No EPSS score is available, and the vulnerability is not listed in CISA KEV. Exploitation requires local access to the ssh‑mcp‑server, meaning the attacker must already have local privileges or otherwise be able to run the tool. However, given the uncertainty about whether the flaw actually exists, the real likelihood and impact remain indeterminate, and the overall risk should be considered contingent on further confirmation.
OpenCVE Enrichment