CVE-2025-61489

MEDIUM

sonirico mcp-shell <0.3.1 - Command Injection

Title source: llm
STIX 2.1

Description

A command injection vulnerability in the shell_exec function of sonirico mcp-shell v0.3.1 allows attackers to execute arbitrary commands via supplying a crafted command string.

Scores

CVSS v3 6.5
EPSS 0.0085
EPSS Percentile 53.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-77
Status published
Products (1)
sonirico/mcp-shell 0.3.1
Published Jan 07, 2026
Tracked Since Feb 18, 2026