Impact
A flaw in the execute_command function of Sunwood‑ai‑labs command‑executor‑mcp‑server allows an attacker to supply arbitrary shell commands that are executed on the underlying operating system. The vulnerability is a classic OS command injection (CWE‑77 and CWE‑78) and provides remote attackers the ability to run any command with the privileges of the service. The impact includes data theft, modification and complete compromise of the host where the MCP server is running.
Affected Systems
The affected product is Sunwood‑ai‑labs command‑executor‑mcp‑server version 0.1.0 and all earlier versions. No other vendors or product versions are listed.
Risk and Exploitability
The CVSS score of 6.9 indicates a medium severity with potential for high impact if exploited. The EPSS score is currently unavailable, and the vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed exploits yet. However, the disclosure is public and the server opens a remote interface, which is the inferred attack vector. Any exposed instance remains at high risk until mitigated.
OpenCVE Enrichment