Command Injection Vulnerability in Sonirico MCP-Shell by Sonirico
CVE-2025-61489
6.5MEDIUM
What is CVE-2025-61489?
A command injection vulnerability exists within the shell_exec function of Sonirico's MCP-Shell v0.3.1. This flaw enables attackers to supply a malicious command string, which can lead to the execution of arbitrary commands on the host system. Proper validation and sanitization of user inputs are crucial to mitigate this security risk.
