CVE-2026-55582
mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, the default security.yaml allows /usr/bin/git, while security.go omits ! from containsShellMetacharacters and containsDangerousShellConstructs and applies no per-executable argument policy. A caller of the shell_exec MCP tool can provide the command argument /usr/bin/git -c alias.pwn=!<arbitrary-command>, causing Git to create a shell alias and execute arbitrary OS commands as the mcp-shell process user. The default Docker image runs as mcpuser with Git installed and secure mode enabled, so the bypass is exploitable in the default deployment without additional authentication beyond MCP connectivity. This issue is fixed in version 0.6.0.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Base score: 8.4
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.27%
- Percentile among all scored CVEs: 17
- Score date: 10/5/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
🎯 ATT&CK techniques
How this vulnerability is exploited and what the attacker gains, in MITRE ATT&CK terms.
- Exploitation
T1068Exploitation for Privilege Escalationprivilege escalation75 % - Primary impact
T1059Command and Scripting Interpreterexecution85 % - Secondary impact
T1078Valid Accountsstealth · persistence · privilege escalation · initial access60 %
Acceso local (AV:L) sin interacción permite escalada mediante bypass de validación en mcp-shell. Ejecución de comandos arbitrarios como usuario mcpuser vía alias malicioso de Git; acceso a cuenta local implícita.
Inferred by our analysis agent from the official description, CVSS vector and CWE, and checked by a supervisor. May contain errors.
🛡️ ATT&CK mitigations that cover these techniques
Affected technologies (2)
⚠ AI-inferred from the description — NVD hasn't analyzed this CVE yet, these aren't verified CPEs.
CWEs
- CWE-78
References
- https://github.com/sonirico/mcp-shell/commit/f31377fce6ec31114e5a4398c0e5270552bce09f
- https://github.com/sonirico/mcp-shell/pull/16
- https://github.com/sonirico/mcp-shell/releases/tag/v0.6.0
- https://github.com/sonirico/mcp-shell/security/advisories/GHSA-74hp-mggr-hv58
- https://github.com/sonirico/mcp-shell/security/advisories/GHSA-74hp-mggr-hv58
Raw JSON (NVD)
Show
{
"id": "CVE-2026-55582",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-55582",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2026-08-28T22:28:14.548495Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.4,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.5
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "sonirico",
"product": "mcp-shell",
"versions": [
{
"status": "affected",
"version": "< 0.6.0"
}
]
}
]
}
],
"published": "2026-08-25T16:16:55.650",
"references": [
{
"url": "https://github.com/sonirico/mcp-shell/commit/f31377fce6ec31114e5a4398c0e5270552bce09f",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/sonirico/mcp-shell/pull/16",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/sonirico/mcp-shell/releases/tag/v0.6.0",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/sonirico/mcp-shell/security/advisories/GHSA-74hp-mggr-hv58",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/sonirico/mcp-shell/security/advisories/GHSA-74hp-mggr-hv58",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-78"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, the default security.yaml allows /usr/bin/git, while security.go omits ! from containsShellMetacharacters and containsDangerousShellConstructs and applies no per-executable argument policy. A caller of the shell_exec MCP tool can provide the command argument /usr/bin/git -c alias.pwn=!<arbitrary-command>, causing Git to create a shell alias and execute arbitrary OS commands as the mcp-shell process user. The default Docker image runs as mcpuser with Git installed and secure mode enabled, so the bypass is exploitable in the default deployment without additional authentication beyond MCP connectivity. This issue is fixed in version 0.6.0."
}
],
"lastModified": "2026-09-09T21:07:31.353",
"sourceIdentifier": "security-advisories@github.com"
}