CRITICAL 10.0 PyPI
terminal-controller-mcp vulnerable to Command Injection
GHSA-h4rf-624j-gj33 · CVE-2025-61492 · PYSEC-2026-551
Published · Modified
Description
A command injection vulnerability in the execute_command function of terminal-controller-mcp 0.1.7 allows attackers to execute arbitrary commands via a crafted input.
Ready to move
Start Securing
Free, no credit card | First findings in minutes