Skip to content

MCPA-2025-0010

criticalrce-vectors

adb-mcp command injection in inspect_ui tool (CVE-2025-59834)

adb-mcp through 0.1.0 builds adb shell command lines from unvalidated tool input (e.g. the `device` argument) and executes them via Node.js `child_process.exec`, allowing shell metacharacter injection and remote code execution on the host running the server. No fixed release was available at publication.

Affected packages

EcosystemPackageAffected versions
npmadb-mcp
>= 0, <= 0.1.0
No patched version at time of advisory publication; remove the server or restrict it to trusted input.

Identifiers

CVE-2025-59834GHSA-54j7-grvr-9xwgCWE-78

References

Timeline

  • Published: 2025-09-24

← All advisories