sonirico has 3 CVEs on record. 3 were published in the last 90 days. The busiest recent month was August 2026 with 3. The median CVSS is 8.4 (high). The most common weakness class is CWE-78 (3).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 8.4
- Publish → KEV
- —
- Last 90 days
- 3 prev 0
Weakness classes
Products
- github.com/sonirico/mcp-shell 3
Worst active — by depth score
CVE-2026-55582High· 8.4mcp-shell is an MCP server for running shell commands securely, auditably, and on demand46CVE-2026-55581High· 8.4mcp-shell is an MCP server for running shell commands securely, auditably, and on demand46CVE-2026-55580Highmcp-shell is an MCP server for running shell commands securely, auditably, and on demand41
sonirico vulnerabilities
CVEs affecting sonirico, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2026-55582High· 8.4mcp-shell is an MCP server for running shell commands securely, auditably, and on demand
mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, the default security.yaml allows /usr/bin/git, while security.go omits ! from containsShellMetacharacters and containsDangerousShel…
CVE-2026-55581High· 8.4mcp-shell is an MCP server for running shell commands securely, auditably, and on demand
mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, the default Docker security.yaml includes /bin/bash in allowed_executables, while security.go validates only the first token and ch…
CVE-2026-55580Highmcp-shell is an MCP server for running shell commands securely, auditably, and on demand
mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, config.go initializes Security.Enabled to false, and when MCP_SHELL_SEC_CONFIG_FILE is unset, main.go starts the documented bare-bi…