Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

cli-mcp-server command allowlist bypass via shell operators

cli-mcp-server 0.2.5 contains a command allowlist bypass vulnerability in the _validate_command_with_operators function when ALLOW_SHELL_OPERATORS is enabled. Attackers can use shell command substitution syntax to execute non-allowlisted commands.

Disclosed 4 September 2026 · Record updated 13 September 2026

Impact

Allows execution of non-allowlisted commands when shell operators are enabled

Our coverage

No articles linked to this incident yet.

Sources

  1. github.comhttps://github.com/advisories/GHSA-wfpw-4v5h-6h32