
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-61492 is a critical command injection vulnerability in the execute_command function of terminal-controller-mcp version 0.1.7, a Model Context Protocol (MCP) server for terminal command execution. It allows unauthenticated remote attackers to execute arbitrary system commands via crafted input that bypasses the application's keyword-based filtering mechanism. The vulnerability was disclosed on January 7, 2026, and affects all versions up to and including 0.1.7. It carries a CVSS v3.1 base score of 10.0 (Critical), assigned by CISA-ADP (Github Advisory, Red Hat CVE).
The root cause is CWE-77 (Improper Neutralization of Special Elements used in a Command), stemming from an inadequate blacklist-based input validation approach in terminal_controller.py. The security check (lines 115–118) only blocks exact contiguous occurrences of a small set of dangerous keywords (e.g., rm -rf /, mkfs), but the command string is subsequently passed to a shell for execution. Attackers can bypass this filter by fragmenting restricted commands using shell features such as command substitution ($()), concatenation, and execution substitution — for example, echo "$($(echo -n m; echo -n k; echo -n f; echo -n s))" reconstructs mkfs at runtime without triggering the keyword filter. Because user-controlled input is passed directly to a shell context without sanitization or allowlisting, any arbitrary command can be injected and executed (GitHub Issue #7, Github Advisory).
Successful exploitation grants an unauthenticated remote attacker full arbitrary command execution on the host system running the MCP server, with the same privileges as the server process. This results in complete compromise of confidentiality (data exfiltration), integrity (file modification, malware installation), and availability (service disruption or destruction). Given the server's design to interact with the local file system and terminal, exploitation could enable lateral movement, credential theft, and persistent backdoor installation (Github Advisory, Red Hat CVE).
A proof-of-concept exploit demonstrating the bypass technique is publicly available in the GitHub issue tracker for the project (GitHub Issue #7). The vulnerability requires no authentication, no user interaction, and has low attack complexity, making it trivially exploitable by any network-accessible attacker. The EPSS score is approximately 0.59% (70th percentile), indicating a moderate near-term exploitation probability. There is no current evidence of active in-the-wild exploitation or threat actor attribution, and the vulnerability is not listed in the CISA KEV catalog as of the time of this report (Github Advisory, Feedly).
terminal-controller-mcp version 0.1.7, which may be exposed via MCP-compatible clients such as Claude Desktop or Cursor. Scan for open MCP server endpoints or review configuration files (e.g., claude_desktop_config.json) if accessible.mkfs, use: echo "$($(echo -n m; echo -n k; echo -n f; echo -n s))".tools/call request to the execute_command tool with the malicious payload:{
"method": "tools/call",
"params": {
"name": "execute_command",
"arguments": {
"command": "echo \"$($(echo -n m; echo -n k; echo -n f; echo -n s))\"",
"timeout": 30
},
"_meta": { "progressToken": 23 }
}
}$(), ;, |, &) in the command parameter; outbound connections from the MCP server process to unknown external IPs.execute_command calls with obfuscated or fragmented command strings (e.g., echo -n m; echo -n k; echo -n f; echo -n s); repeated failed or unusual command executions in command history (get_command_history).bash, sh, curl, wget, python, nc); processes running under the MCP server's user account that are unrelated to normal terminal operations.~/.ssh/authorized_keys, /etc/cron.d/, /tmp/); unexpected scripts or binaries created by the MCP server process user (GitHub Issue #7, Github Advisory).The GitHub Advisory (GHSA-h4rf-624j-gj33) lists all versions <= 0.1.7 as affected with no patched version currently published; the repository was archived by the owner on March 3, 2026, indicating the project is no longer maintained. Users should immediately remove or disable terminal-controller-mcp from their MCP client configurations. As interim mitigations: implement network segmentation to restrict access to the MCP server endpoint, monitor for suspicious command execution patterns, and consider replacing the tool with an actively maintained alternative that uses allowlist-based command validation or disables shell interpretation entirely (Github Advisory, Feedly).
The vulnerability received brief coverage from security news aggregators including TheHackerWire on Mastodon and Bluesky shortly after disclosure. Red Hat tracked the CVE and published an advisory entry. No significant vendor statements, in-depth researcher write-ups, or major media coverage have been identified beyond automated vulnerability database entries and social media posts from security news accounts (Red Hat CVE).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."