mcp-shell Multiple Command Execution Vulnerabilities
Three vulnerabilities in mcp-shell prior to version 0.6.0 allow attackers to execute arbitrary OS commands through the shell_exec MCP tool due to insecure default configuration, insufficient command validation, and shell metacharacter bypass in Git alias handling.
Disclosed 25 August 2026 · Record updated 13 September 2026
Impact
An attacker with MCP connectivity can execute unrestricted OS commands as the mcp-shell process user in default deployments, including Docker containers running as mcpuser.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-55580
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-55581
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-55582
