


Perceptive Security
SOC/SIEM Consultancy

A security vulnerability has been detected in tufantunc ssh-mcp up to 1.5.0. The affected element is the function shell.write of the file src/index.ts. Such man…
Published:
25 april 2026 om 22:00:00
Alert date:
26 april 2026 om 14:00:45
Source:
nvd.nist.gov
Supply Chain & Dependencies, Network Infrastructure
A command injection vulnerability has been identified in tufantunc ssh-mcp library up to version 1.5.0. The vulnerability affects the shell.write function in src/index.ts file, where manipulation of the Description argument leads to command injection. The attack vector is local and the exploit has been publicly disclosed. The maintainers were notified through a GitHub issue but have not responded yet, making this a concerning unpatched vulnerability.
Technical details
Mitigation steps:
Affected products:
tufantunc ssh-mcp
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-7039
https://github.com/tufantunc/ssh-mcp/
https://github.com/tufantunc/ssh-mcp/issues/44
https://vuldb.com/submit/798528
https://vuldb.com/vuln/359619
https://vuldb.com/vuln/359619/cti
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
