PT-2025-48575 · Mcp Watch · Mcp-Watch
Published
2025-12-01
·
Updated
2026-02-06
·
CVE-2025-66401
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
MCP Watch versions 0.1.2 and earlier
Description
MCP Watch, a security scanner for Model Context Protocol (MCP) servers, contains a Command Injection issue in the
cloneRepo method of the MCPScanner class. The application directly passes the githubUrl argument, supplied by a user, to a system shell using execSync without proper sanitization. This allows an attacker to execute arbitrary commands on the host machine by appending shell metacharacters to the URL.Recommendations
Versions prior to 0.1.2 are vulnerable.
Exploit
Fix
RCE
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mcp-Watch