


Perceptive Security
SOC/SIEM Consultancy

mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, the default security.yaml allows /usr/bin/git, while s…
Published:
25 August 2026 at 00:00:00
Alert date:
25 August 2026 at 19:07:30
Source:
nvd.nist.gov
Security Tools, Web Technologies, Zero-Day Vulnerabilities
CVE-2026-55582 affects mcp-shell, an MCP server for running shell commands securely. Prior to version 0.6.0, the default security.yaml configuration permits /usr/bin/git, while the security.go file fails to include the '!' character in its shell metacharacter and dangerous construct checks. This oversight, combined with no per-executable argument policy, allows an attacker to pass a crafted Git -c alias argument to execute arbitrary OS commands. The exploit leverages Git's alias feature with shell escape syntax (!<command>) to bypass security controls. The default Docker deployment runs as mcpuser with Git installed and secure mode enabled, making it exploitable without additional authentication beyond MCP connectivity. The vulnerability is exploitable in default configurations, raising its risk profile significantly. The issue has been patched in version 0.6.0 of mcp-shell. Users are advised to upgrade immediately to mitigate the risk of arbitrary command execution.
Technical details
Mitigation steps:
Affected products:
mcp-shell (prior to 0.6.0)
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-55582
https://github.com/sonirico/mcp-shell/commit/f31377fce6ec31114e5a4398c0e5270552bce09f
https://github.com/sonirico/mcp-shell/pull/16
https://github.com/sonirico/mcp-shell/releases/tag/v0.6.0
https://github.com/sonirico/mcp-shell/security/advisories/GHSA-74hp-mggr-hv58
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
