Skip to content

Hide Navigation Hide TOC

Command Injection in create-mcp-server-stdio via Unsafe exec() Concatenation (CVE-2025-54994) - ATR-2026-00577 (19130828-672a-5823-8616-1c8816b4c06f)

GitHub Security Advisory GHSA-3ch2-jxxc-v4xf (CVE-2025-54994). The create-mcp-server-stdio npm package builds shell commands by concatenating MCP stdio tool parameters directly into exec(), so shell metacharacters supplied through a tool argument (; | && $() backticks) are interpreted by the shell and execute arbitrary commands on the server host (RCE).

Cluster A Galaxy A Cluster B Galaxy B Level
Indirect (a4a55526-2f1f-403b-9691-609e46381e17) MITRE ATLAS Attack Pattern Command Injection in create-mcp-server-stdio via Unsafe exec() Concatenation (CVE-2025-54994) - ATR-2026-00577 (19130828-672a-5823-8616-1c8816b4c06f) Agent Threat Rules 1
LLM Plugin Compromise (adbb0dd5-ff66-4b2f-869f-bfb3fdb45fc8) MITRE ATLAS Attack Pattern Command Injection in create-mcp-server-stdio via Unsafe exec() Concatenation (CVE-2025-54994) - ATR-2026-00577 (19130828-672a-5823-8616-1c8816b4c06f) Agent Threat Rules 1
Indirect (a4a55526-2f1f-403b-9691-609e46381e17) MITRE ATLAS Attack Pattern LLM Prompt Injection (19cd2d12-66ff-487c-a05c-e058b027efc9) MITRE ATLAS Attack Pattern 2