Skip to content

MCPA-2025-0009

criticalrce-vectors

@akoskm/create-mcp-server-stdio command injection via exec in which-app-on-port tool (CVE-2025-54994)

The MCP server scaffold @akoskm/create-mcp-server-stdio before 0.0.13 exposes a `which-app-on-port` tool that concatenates untrusted input into Node.js `child_process.exec`, allowing command injection and remote code execution under the server process's privileges.

Affected packages

EcosystemPackageAffected versions
npm@akoskm/create-mcp-server-stdio
>= 0, < 0.0.13

Identifiers

CVE-2025-54994GHSA-3ch2-jxxc-v4xfCWE-78

References

Timeline

  • Published: 2025-09-08

← All advisories