CRITICAL 10.0 PyPI

terminal-controller-mcp vulnerable to Command Injection

GHSA-h4rf-624j-gj33 · CVE-2025-61492 · PYSEC-2026-551

Published · Modified

Description

A command injection vulnerability in the execute_command function of terminal-controller-mcp 0.1.7 allows attackers to execute arbitrary commands via a crafted input.

Ready to move

Start Securing

Free, no credit card | First findings in minutes