Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

Curation review for GHSA-gvwf-5g64-3vvw: global publication and possible duplicate

Aperta
#9,397 1 commento 0 reazioni 0 assegnatari Vedi su GitHub

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
4/5
Tempo stimato
3-5 giorni
Idoneità per principianti
35/100
Tipo di issue
Funzionalità
Chiarezza
Specificata chiaramente
Stato di attività
Attiva
Stack tecnologico
python
Ambito
security

Direzione di ricerca

Esamina gli advisory del repository GHSA-gvwf-5g64-3vv e GHSA-88qq-fvcm-92qq, insieme ai record CVE/GHSA collegati e all’ambito della correzione della 1.1.3. Confronta il comportamento rimanente dei file di script AWK con l’advisory sovrapposto e determina se questo record debba essere promosso separatamente o consolidato. Il lavoro è completato quando sono documentati la decisione di curatela e qualsiasi azione necessaria relativa a un advisory canonico o a un ritiro.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

Summary

I maintain tumf/mcp-shell-server. Repository advisory GHSA-gvwf-5g64-3vvw was published on 2026-08-02 but is still absent from the global GitHub Advisory Database and OSV.

I have revalidated and corrected the repository advisory against the released versions. I am requesting curation review before requesting a CVE because the remaining vulnerability may overlap another published repository advisory.

Advisory

  • Repository advisory: https://github.com/tumf/mcp-shell-server/security/advisories/GHSA-gvwf-5g64-3vvw
  • Package: mcp-shell-server (pip)
  • Affected versions: <= 1.1.2
  • Patched version: 1.1.3
  • Remaining scoped behavior: when awk is allowlisted, awk -f /dev/stdin accepts an attacker-controlled AWK program through the MCP tool's stdin, allowing external command execution as the server process user
  • CWE: CWE-78, CWE-184
  • Severity currently recorded: High

Scope correction already made

The original report reviewed an older commit and combined tar, git, and AWK vectors. Release-level revalidation found:

  • the reported tar vector was already rejected in 1.1.1 and 1.1.2;
  • the reported git vector was already rejected in 1.1.1 and 1.1.2 and overlaps CVE-2026-85735 / GHSA-56qh-7rgp-wfgr;
  • whitespace-obfuscated awk system() was already rejected before 1.1.2;
  • awk -f /dev/stdin remained accepted in 1.1.1 and 1.1.2 and is rejected in 1.1.3.

The repository advisory has been edited to reflect only the remaining release-level AWK script-file/stdin vulnerability while preserving reporter credit.

Possible overlap

The same 1.1.3 remediation commit also addressed behavior reported in:

That advisory covers sed command execution, GNU find file output, and AWK external file/script access. Both advisories identify 1.1.3 as the patched release, and both include AWK script-file handling.

Request

Could the curation team determine whether:

  1. GHSA-gvwf-5g64-3vvw should be promoted as a separate global advisory; or
  2. it should be treated as a duplicate of or consolidated with GHSA-88qq-fvcm-92qq?

I am intentionally holding the Request CVE action until the duplication/counting question is resolved. If the advisories should be consolidated, please advise which repository advisory should remain canonical and whether GitHub Support must withdraw the duplicate.

Lingua principale
Nessun dato sulla lingua
Stelle
2.5k
Fork
772
Merge medio
3g 18h
PR unite (30g)
48

Guida per i contributori

Apri la guida per i contributori

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di github/advisory-database

Tutte le issue di github/advisory-database

Issue simili

Altre issue su Security

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.