Vendor
A command injection vulnerability in the mcp-bridge.js component of mcp-bridge-api allows remote attackers to execute arbitrary system commands via manipulation of the command/args argument.