Product
high
advisory
MCP-Shell Secure Mode Allowlist Bypass via Shell Interpreter
1 TTPThe mcp-shell tool contains a security bypass where improper validation of command-line arguments allows an attacker to execute arbitrary commands by leveraging a default-allowed shell interpreter.
mcp-shell
command-injection
mcp
container-security
1t
high
advisory
mcp-shell Insecure Configuration and Allowlist Bypass
2 TTPsmcp-shell versions prior to 0.6.0 suffer from default-disabled security settings and insecure allowlists, enabling unauthenticated arbitrary command execution via connected LLM agents.
PoC
mcp-shell
vulnerability
rce
mcp
llm-security
2t