Filtered by vendor Mladensu
Subscriptions
Filtered by product Cli-mcp-server
Subscriptions
Total
1 CVE
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-85660 | 1 Mladensu | 1 Cli-mcp-server | 2026-09-07 | 8.1 High |
| cli-mcp-server 0.2.5 contains a command allowlist bypass vulnerability in the _validate_command_with_operators function when ALLOW_SHELL_OPERATORS is enabled. Attackers can use shell command substitution syntax like $(...) or backticks to execute non-allowlisted commands that bypass the ALLOWED_COMMANDS validation check. | ||||
Page 1 of 1.