{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/cli-mcp-server-0.2.5/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-85660"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["cli-mcp-server (0.2.5)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","command-injection","execution"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThe cli-mcp-server package version 0.2.5 contains a vulnerability in the _validate_command_with_operators function that can be triggered when the ALLOW_SHELL_OPERATORS configuration is enabled. This flaw allows an attacker to bypass the defined ALLOWED_COMMANDS validation check by leveraging shell command substitution syntax, such as $(...) or backticks. When an attacker provides a crafted input string containing these shell metacharacters, the validation logic fails to correctly filter the command execution, leading to the execution of non-allowlisted and potentially malicious commands. This vulnerability highlights a failure in input sanitization within the server's command processing logic, posing a significant risk for systems that rely on this package to restrict command execution environments. Defenders should identify instances of cli-mcp-server and ensure they are updated to a non-vulnerable version, or disable the ALLOW_SHELL_OPERATORS feature if command execution flexibility is not required.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the execution of arbitrary, non-allowlisted shell commands, potentially leading to unauthorized system access, data exfiltration, or further lateral movement depending on the privileges of the process hosting the cli-mcp-server.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify and audit all applications currently using cli-mcp-server version 0.2.5.\u003c/li\u003e\n\u003cli\u003eUpdate cli-mcp-server to a version that patches the _validate_command_with_operators validation logic.\u003c/li\u003e\n\u003cli\u003eIf an update is not immediately feasible, set ALLOW_SHELL_OPERATORS to false to mitigate the specific bypass vector.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-04T15:28:40Z","date_published":"2026-09-04T15:28:40Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cli-mcp-server-bypass/","summary":"The cli-mcp-server package version 0.2.5 contains a vulnerability in the _validate_command_with_operators function allowing attackers to bypass command allowlists via shell substitution.","title":"Command Allowlist Bypass in cli-mcp-server","url":"https://feed.craftedsignal.io/briefs/2026-09-cli-mcp-server-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cli-Mcp-Server (0.2.5)","version":"https://jsonfeed.org/version/1.1"}