Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

Curation review for GHSA-gvwf-5g64-3vvw: global publication and possible duplicate

未关闭
#9,397 1 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

维护者通常 1 天内回复

还没有人认领这个 Issue。

评估

难度
4/5
预计耗时
3-5 天
新手友好度
35/100
Issue 类型
功能
描述清晰度
描述清楚
活跃度
活跃
技术栈
python
领域
security

调研方向

审查仓库公告 GHSA-gvwf-5g64-3vv 和 GHSA-88qq-fvcm-92qq,以及关联的 CVE/GHSA 记录和 1.1.3 的修复范围。将剩余的 AWK 脚本文件行为与重叠的公告进行比较,并确定此记录是否应单独提升或合并。完成标准是记录整理决定,以及任何必要的规范公告或撤回操作。

由索引模型根据 Issue 内容生成。

描述

Summary

I maintain tumf/mcp-shell-server. Repository advisory GHSA-gvwf-5g64-3vvw was published on 2026-08-02 but is still absent from the global GitHub Advisory Database and OSV.

I have revalidated and corrected the repository advisory against the released versions. I am requesting curation review before requesting a CVE because the remaining vulnerability may overlap another published repository advisory.

Advisory

  • Repository advisory: https://github.com/tumf/mcp-shell-server/security/advisories/GHSA-gvwf-5g64-3vvw
  • Package: mcp-shell-server (pip)
  • Affected versions: <= 1.1.2
  • Patched version: 1.1.3
  • Remaining scoped behavior: when awk is allowlisted, awk -f /dev/stdin accepts an attacker-controlled AWK program through the MCP tool's stdin, allowing external command execution as the server process user
  • CWE: CWE-78, CWE-184
  • Severity currently recorded: High

Scope correction already made

The original report reviewed an older commit and combined tar, git, and AWK vectors. Release-level revalidation found:

  • the reported tar vector was already rejected in 1.1.1 and 1.1.2;
  • the reported git vector was already rejected in 1.1.1 and 1.1.2 and overlaps CVE-2026-85735 / GHSA-56qh-7rgp-wfgr;
  • whitespace-obfuscated awk system() was already rejected before 1.1.2;
  • awk -f /dev/stdin remained accepted in 1.1.1 and 1.1.2 and is rejected in 1.1.3.

The repository advisory has been edited to reflect only the remaining release-level AWK script-file/stdin vulnerability while preserving reporter credit.

Possible overlap

The same 1.1.3 remediation commit also addressed behavior reported in:

That advisory covers sed command execution, GNU find file output, and AWK external file/script access. Both advisories identify 1.1.3 as the patched release, and both include AWK script-file handling.

Request

Could the curation team determine whether:

  1. GHSA-gvwf-5g64-3vvw should be promoted as a separate global advisory; or
  2. it should be treated as a duplicate of or consolidated with GHSA-88qq-fvcm-92qq?

I am intentionally holding the Request CVE action until the duplication/counting question is resolved. If the advisories should be consolidated, please advise which repository advisory should remain canonical and whether GitHub Support must withdraw the duplicate.

主要语言
没有语言数据
星标
2.5k
派生
772
平均合并
5 天 12 小时
30 天内合并 PR
68

环境准备

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

github/advisory-database 的其他 Issue

查看 github/advisory-database 的全部 Issue

相似的 Issue

更多 Security Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。