Impact
A vulnerability exists in the mcp-bridge.js component of INQUIRELAB mcp-bridge-api, where manipulation of the command/args argument can lead to arbitrary code execution on the host. The flaw resides in an unknown function within the Servers Endpoint, allowing a remote attacker to inject and run system commands through the API. This may compromise confidentiality, integrity, and availability of the underlying system if the API is exposed to untrusted clients.
Affected Systems
The affected product is INQUIRELAB mcp-bridge-api, which follows a rolling‑release model without explicit version tags for the vulnerable state. All releases prior to the fix (commit b30a82aa1d1d1139e0de846c41c8aadee6e06114) are impacted. The vulnerability is located in the mcp-bridge.js file’s Servers Endpoint function and can affect any deployment that exposes this endpoint.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity, and the EPSS score is currently unavailable, but the lack of a KEV listing does not mitigate potential exploitation in a network‑exposed scenario. An attacker who can reach the mcp-bridge-api endpoint can send crafted request payloads to trigger the command injection, thereby executing arbitrary shell commands on the host. The pull request addressing this issue has not yet been merged, so no public patch is available at this time, increasing the window of exposure.
OpenCVE Enrichment