MCPA-2025-0008
highrce-vectors
mcp-package-docs command injection in several tools (CVE-2025-54073)
mcp-package-docs versions through 0.1.27 pass unsanitized tool input into `child_process.exec`, enabling shell metacharacter injection and remote code execution under the server process's privileges. Fixed in 0.1.28; the package has since been deprecated on npm and the repository archived.
Affected packages
| Ecosystem | Package | Affected versions |
|---|---|---|
| npm | mcp-package-docs | >= 0, < 0.1.28 Package deprecated on npm after the fix; prefer removing it entirely. |
Identifiers
CVE-2025-54073GHSA-vf9j-h32g-2764CWE-78
References
- advisory https://github.com/advisories/GHSA-vf9j-h32g-2764
- advisory https://nvd.nist.gov/vuln/detail/CVE-2025-54073
- fix https://github.com/sammcj/mcp-package-docs/releases/tag/v0.1.28
Timeline
- Published: 2025-07-18