Curation review for GHSA-gvwf-5g64-3vvw: global publication and possible duplicate
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 35/100
Research direction
Review the repository advisories GHSA-gvwf-5g64-3vvw and GHSA-88qq-fvcm-92qq, along with the linked CVE/GHSA records and the 1.1.3 remediation scope. Compare the remaining AWK script-file behavior with the overlapping advisory and determine whether this record should be promoted separately or consolidated. Done means documenting the curation decision and any required canonical-advisory or withdrawal action.
Written by the indexing model from the issue text.
Description
Summary
I maintain tumf/mcp-shell-server. Repository advisory GHSA-gvwf-5g64-3vvw was published on 2026-08-02 but is still absent from the global GitHub Advisory Database and OSV.
I have revalidated and corrected the repository advisory against the released versions. I am requesting curation review before requesting a CVE because the remaining vulnerability may overlap another published repository advisory.
Advisory
- Repository advisory: https://github.com/tumf/mcp-shell-server/security/advisories/GHSA-gvwf-5g64-3vvw
- Package:
mcp-shell-server(pip) - Affected versions:
<= 1.1.2 - Patched version:
1.1.3 - Remaining scoped behavior: when
awkis allowlisted,awk -f /dev/stdinaccepts an attacker-controlled AWK program through the MCP tool's stdin, allowing external command execution as the server process user - CWE: CWE-78, CWE-184
- Severity currently recorded: High
Scope correction already made
The original report reviewed an older commit and combined tar, git, and AWK vectors. Release-level revalidation found:
- the reported tar vector was already rejected in 1.1.1 and 1.1.2;
- the reported git vector was already rejected in 1.1.1 and 1.1.2 and overlaps
CVE-2026-85735/GHSA-56qh-7rgp-wfgr; - whitespace-obfuscated
awk system()was already rejected before 1.1.2; awk -f /dev/stdinremained accepted in 1.1.1 and 1.1.2 and is rejected in 1.1.3.
The repository advisory has been edited to reflect only the remaining release-level AWK script-file/stdin vulnerability while preserving reporter credit.
Possible overlap
The same 1.1.3 remediation commit also addressed behavior reported in:
That advisory covers sed command execution, GNU find file output, and AWK external file/script access. Both advisories identify 1.1.3 as the patched release, and both include AWK script-file handling.
Request
Could the curation team determine whether:
GHSA-gvwf-5g64-3vvwshould be promoted as a separate global advisory; or- it should be treated as a duplicate of or consolidated with
GHSA-88qq-fvcm-92qq?
I am intentionally holding the Request CVE action until the duplication/counting question is resolved. If the advisories should be consolidated, please advise which repository advisory should remain canonical and whether GitHub Support must withdraw the duplicate.
- Dominant language
- No language data
- Stars
- 2.5k
- Forks
- 772
- Avg merge
- 3d 18h
- Merged PRs (30d)
- 48
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from github/advisory-database
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
github/advisory-database#9255 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
github/advisory-database#9164 · 1 reaction ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
github/advisory-database#8994 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
github/advisory-database#8898 · 4 comments · 1 reaction ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
github/advisory-database#8841 ·
All issues in github/advisory-database
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
punkpeye/mcp-remote#369 ·
-
Mend: dependency security vulnerability untriaged
Difficulty 1/5 Under an hour Newbie friendliness 86/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
-
bug
Difficulty 1/5 Under an hour Newbie friendliness 90/100
cisagov/vulnrichment#337 ·
-
bug DUP Reservations
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
bcgov/reserve-rec-public#896 ·