Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 04 Sep 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | cli-mcp-server 0.2.5 contains a command allowlist bypass vulnerability in the _validate_command_with_operators function when ALLOW_SHELL_OPERATORS is enabled. Attackers can use shell command substitution syntax like $(...) or backticks to execute non-allowlisted commands that bypass the ALLOWED_COMMANDS validation check. | |
| Title | cli-mcp-server 0.2.5 Command Allowlist Bypass via Shell Substitution | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-04T14:32:18.149Z
Reserved: 2026-09-04T13:32:27.594Z
Link: CVE-2026-85660
No data.
Status : Received
Published: 2026-09-04T15:17:43.490
Modified: 2026-09-04T15:17:43.490
Link: CVE-2026-85660
No data.
OpenCVE Enrichment
No data.