Impact
The ssh‑mcp component contains a local command injection flaw within the shell.write function exposed in src/index.ts. An attacker controlling the Description parameter can inject arbitrary shell commands. This weakness falls under CWE‑74 and CWE‑77, allowing illicit command execution in the context of the running process. Because the vulnerability requires local access, it could be leveraged by operators or compromised local accounts to gain escalated privileges or disrupt services.
Affected Systems
vulnerable versions of tufantunc ssh‑mcp released up to 1.5.0 are affected. System administrators running any of these releases should review their deployment and plan an update as soon as a fixed version becomes available. No other product versions are currently indicated as impacted.
Risk and Exploitability
The CVSS score of 8.5 indicates high severity, but the EPSS score is less than 1%, suggesting low current exploitation probability. The vulnerability remains unpublished in the CISA KEV catalog. The attack vector is local, requiring the attacker to have access to the host where ssh‑mcp is running. Although publicly disclosed, the maintainer has not yet released a fix, so users must rely on mitigation until an official patch arrives.
OpenCVE Enrichment