Skip to content

MCPA-2025-0008

highrce-vectors

mcp-package-docs command injection in several tools (CVE-2025-54073)

mcp-package-docs versions through 0.1.27 pass unsanitized tool input into `child_process.exec`, enabling shell metacharacter injection and remote code execution under the server process's privileges. Fixed in 0.1.28; the package has since been deprecated on npm and the repository archived.

Affected packages

EcosystemPackageAffected versions
npmmcp-package-docs
>= 0, < 0.1.28
Package deprecated on npm after the fix; prefer removing it entirely.

Identifiers

CVE-2025-54073GHSA-vf9j-h32g-2764CWE-78

References

Timeline

  • Published: 2025-07-18

← All advisories