Curation review for GHSA-gvwf-5g64-3vvw: global publication and possible duplicate
まだ誰も着手していません。
評価
調査の方向性
リポジトリのアドバイザリ GHSA-gvwf-5g64-3vv と GHSA-88qq-fvcm-92qq、およびリンクされている CVE/GHSA レコードと 1.1.3 の修正範囲を確認してください。残存する AWK スクリプトファイルの挙動を重複するアドバイザリと比較し、このレコードを個別に昇格するべきか、統合するべきかを判断してください。完了条件は、キュレーションの判断と、必要な canonical-advisory または撤回の対応を文書化することです。
索引モデルが issue の本文から書いたものです。
説明
Summary
I maintain tumf/mcp-shell-server. Repository advisory GHSA-gvwf-5g64-3vvw was published on 2026-08-02 but is still absent from the global GitHub Advisory Database and OSV.
I have revalidated and corrected the repository advisory against the released versions. I am requesting curation review before requesting a CVE because the remaining vulnerability may overlap another published repository advisory.
Advisory
- Repository advisory: https://github.com/tumf/mcp-shell-server/security/advisories/GHSA-gvwf-5g64-3vvw
- Package:
mcp-shell-server(pip) - Affected versions:
<= 1.1.2 - Patched version:
1.1.3 - Remaining scoped behavior: when
awkis allowlisted,awk -f /dev/stdinaccepts an attacker-controlled AWK program through the MCP tool's stdin, allowing external command execution as the server process user - CWE: CWE-78, CWE-184
- Severity currently recorded: High
Scope correction already made
The original report reviewed an older commit and combined tar, git, and AWK vectors. Release-level revalidation found:
- the reported tar vector was already rejected in 1.1.1 and 1.1.2;
- the reported git vector was already rejected in 1.1.1 and 1.1.2 and overlaps
CVE-2026-85735/GHSA-56qh-7rgp-wfgr; - whitespace-obfuscated
awk system()was already rejected before 1.1.2; awk -f /dev/stdinremained accepted in 1.1.1 and 1.1.2 and is rejected in 1.1.3.
The repository advisory has been edited to reflect only the remaining release-level AWK script-file/stdin vulnerability while preserving reporter credit.
Possible overlap
The same 1.1.3 remediation commit also addressed behavior reported in:
That advisory covers sed command execution, GNU find file output, and AWK external file/script access. Both advisories identify 1.1.3 as the patched release, and both include AWK script-file handling.
Request
Could the curation team determine whether:
GHSA-gvwf-5g64-3vvwshould be promoted as a separate global advisory; or- it should be treated as a duplicate of or consolidated with
GHSA-88qq-fvcm-92qq?
I am intentionally holding the Request CVE action until the duplication/counting question is resolved. If the advisories should be consolidated, please advise which repository advisory should remain canonical and whether GitHub Support must withdraw the duplicate.
- 主要言語
- 言語のデータがありません
- スター
- 2.5k
- フォーク
- 772
- 平均マージ
- 3日 15時間
- マージ済み PR(30日)
- 46
コントリビューションガイド
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
github/advisory-database のほかの issue
-
難易度 2/5 1〜3時間 初心者へのやさしさ 68/100
github/advisory-database#9255 ·
-
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
github/advisory-database#9164 · リアクション 1 件 ·
-
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
github/advisory-database#8994 ·
-
難易度 2/5 1〜3時間 初心者へのやさしさ 68/100
github/advisory-database#8898 · コメント 4 件 · リアクション 1 件 ·
-
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
github/advisory-database#8841 ·
github/advisory-database の issue をすべて見る
似ている issue
-
blocklist removal
難易度 2/5 1〜3時間 初心者へのやさしさ 65/100
MetaMask/eth-phishing-detect#296544 ·
-
難易度 2/5 1〜3時間 初心者へのやさしさ 70/100
Azure/azure-functions-docker#1257 ·
-
area:proxy bug security severity:low track:open-source
難易度 2/5 1〜3時間 初心者へのやさしさ 75/100
-
bug server
難易度 2/5 1〜3時間 初心者へのやさしさ 70/100
-
難易度 2/5 1〜3時間 初心者へのやさしさ 70/100
bytedance/UI-TARS-desktop#2009 · コメント 1 件 ·