Curation review for GHSA-gvwf-5g64-3vvw: global publication and possible duplicate
维护者通常 1 天内回复
还没有人认领这个 Issue。
评估
调研方向
审查仓库公告 GHSA-gvwf-5g64-3vv 和 GHSA-88qq-fvcm-92qq,以及关联的 CVE/GHSA 记录和 1.1.3 的修复范围。将剩余的 AWK 脚本文件行为与重叠的公告进行比较,并确定此记录是否应单独提升或合并。完成标准是记录整理决定,以及任何必要的规范公告或撤回操作。
由索引模型根据 Issue 内容生成。
描述
Summary
I maintain tumf/mcp-shell-server. Repository advisory GHSA-gvwf-5g64-3vvw was published on 2026-08-02 but is still absent from the global GitHub Advisory Database and OSV.
I have revalidated and corrected the repository advisory against the released versions. I am requesting curation review before requesting a CVE because the remaining vulnerability may overlap another published repository advisory.
Advisory
- Repository advisory: https://github.com/tumf/mcp-shell-server/security/advisories/GHSA-gvwf-5g64-3vvw
- Package:
mcp-shell-server(pip) - Affected versions:
<= 1.1.2 - Patched version:
1.1.3 - Remaining scoped behavior: when
awkis allowlisted,awk -f /dev/stdinaccepts an attacker-controlled AWK program through the MCP tool's stdin, allowing external command execution as the server process user - CWE: CWE-78, CWE-184
- Severity currently recorded: High
Scope correction already made
The original report reviewed an older commit and combined tar, git, and AWK vectors. Release-level revalidation found:
- the reported tar vector was already rejected in 1.1.1 and 1.1.2;
- the reported git vector was already rejected in 1.1.1 and 1.1.2 and overlaps
CVE-2026-85735/GHSA-56qh-7rgp-wfgr; - whitespace-obfuscated
awk system()was already rejected before 1.1.2; awk -f /dev/stdinremained accepted in 1.1.1 and 1.1.2 and is rejected in 1.1.3.
The repository advisory has been edited to reflect only the remaining release-level AWK script-file/stdin vulnerability while preserving reporter credit.
Possible overlap
The same 1.1.3 remediation commit also addressed behavior reported in:
That advisory covers sed command execution, GNU find file output, and AWK external file/script access. Both advisories identify 1.1.3 as the patched release, and both include AWK script-file handling.
Request
Could the curation team determine whether:
GHSA-gvwf-5g64-3vvwshould be promoted as a separate global advisory; or- it should be treated as a duplicate of or consolidated with
GHSA-88qq-fvcm-92qq?
I am intentionally holding the Request CVE action until the duplication/counting question is resolved. If the advisories should be consolidated, please advise which repository advisory should remain canonical and whether GitHub Support must withdraw the duplicate.
- 主要语言
- 没有语言数据
- 星标
- 2.5k
- 派生
- 772
- 平均合并
- 5 天 12 小时
- 30 天内合并 PR
- 68
环境准备
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
github/advisory-database 的其他 Issue
-
难度 2/5 1-3 小时 新手友好度 68/100
github/advisory-database#9255 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 72/100
github/advisory-database#9164 · 1 个 reaction ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 72/100
github/advisory-database#8994 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 68/100
github/advisory-database#8898 · 4 条评论 · 1 个 reaction ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 72/100
github/advisory-database#8841 ·
维护者通常 1 天内回复
查看 github/advisory-database 的全部 Issue
相似的 Issue
-
难度 2/5 1-3 小时 新手友好度 88/100
ComplianceAsCode/content#15152 ·
维护者通常 3 天内回复
-
难度 2/5 1-3 小时 新手友好度 84/100
维护者通常 1 天内回复
-
priority/4/normal status/needs-triage type/bug/unconfirmed
难度 2/5 1-3 小时 新手友好度 78/100
authelia/authelia#13292 · 1 条评论 ·
维护者通常 1 天内回复
-
Mend: dependency security vulnerability untriaged
难度 2/5 1-3 小时 新手友好度 64/100
opensearch-project/OpenSearch-Dashboards#12822 ·
维护者通常 1 天内回复
-
blocklist removal
难度 2/5 1-3 小时 新手友好度 72/100
MetaMask/eth-phishing-detect#298080 ·
维护者通常 1 天内回复