Impact
Agentic-Flow’s MCP server tools previously allowed unsanitized tool parameters—such as agent, task, name, language, and agentdb—to be interpolated directly into shell command strings passed to execSync(). This flaw permits an attacker who can influence those parameters to execute arbitrary OS commands with the privileges of the MCP server user, potentially compromising the entire system.
Affected Systems
Vulnerable releases of the Ruvnet Agentic-Flow platform before version 2.0.14 are affected. The flaw exists in several server modules, including standalone-stdio, fastmcp servers for Claude Flow, stdio-full, HTTP streaming, SSE, and various tool execution modules. Users running any of these modules before the 2.0.14 update are at risk.
Risk and Exploitability
The CVSS score of 8.8 classifies this as high severity. The EPSS score of less than 1% indicates that, at present, the probability of exploitation is very low, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector involves an attacker sending crafted requests that manipulate the vulnerable parameters; successful exploitation requires that the MCP server’s tools accept user input and that the attacker can reach the MCP server interface, either locally or over a network that has not been adequately secured.
OpenCVE Enrichment