MCPA-2025-0010
criticalrce-vectors
adb-mcp command injection in inspect_ui tool (CVE-2025-59834)
adb-mcp through 0.1.0 builds adb shell command lines from unvalidated tool input (e.g. the `device` argument) and executes them via Node.js `child_process.exec`, allowing shell metacharacter injection and remote code execution on the host running the server. No fixed release was available at publication.
Affected packages
| Ecosystem | Package | Affected versions |
|---|---|---|
| npm | adb-mcp | >= 0, <= 0.1.0 No patched version at time of advisory publication; remove the server or restrict it to trusted input. |
Identifiers
CVE-2025-59834GHSA-54j7-grvr-9xwgCWE-78
References
- advisory https://github.com/advisories/GHSA-54j7-grvr-9xwg
- advisory https://nvd.nist.gov/vuln/detail/CVE-2025-59834
Timeline
- Published: 2025-09-24