CVE-2025-61492: 
Python vulnerability analysis and mitigation

Overview

CVE-2025-61492 is a critical command injection vulnerability in the execute_command function of terminal-controller-mcp version 0.1.7, a Model Context Protocol (MCP) server for terminal command execution. It allows unauthenticated remote attackers to execute arbitrary system commands via crafted input that bypasses the application's keyword-based filtering mechanism. The vulnerability was disclosed on January 7, 2026, and affects all versions up to and including 0.1.7. It carries a CVSS v3.1 base score of 10.0 (Critical), assigned by CISA-ADP (Github Advisory, Red Hat CVE).

Technical details

The root cause is CWE-77 (Improper Neutralization of Special Elements used in a Command), stemming from an inadequate blacklist-based input validation approach in terminal_controller.py. The security check (lines 115–118) only blocks exact contiguous occurrences of a small set of dangerous keywords (e.g., rm -rf /, mkfs), but the command string is subsequently passed to a shell for execution. Attackers can bypass this filter by fragmenting restricted commands using shell features such as command substitution ($()), concatenation, and execution substitution — for example, echo "$($(echo -n m; echo -n k; echo -n f; echo -n s))" reconstructs mkfs at runtime without triggering the keyword filter. Because user-controlled input is passed directly to a shell context without sanitization or allowlisting, any arbitrary command can be injected and executed (GitHub Issue #7, Github Advisory).

Impact

Successful exploitation grants an unauthenticated remote attacker full arbitrary command execution on the host system running the MCP server, with the same privileges as the server process. This results in complete compromise of confidentiality (data exfiltration), integrity (file modification, malware installation), and availability (service disruption or destruction). Given the server's design to interact with the local file system and terminal, exploitation could enable lateral movement, credential theft, and persistent backdoor installation (Github Advisory, Red Hat CVE).

Exploitability

A proof-of-concept exploit demonstrating the bypass technique is publicly available in the GitHub issue tracker for the project (GitHub Issue #7). The vulnerability requires no authentication, no user interaction, and has low attack complexity, making it trivially exploitable by any network-accessible attacker. The EPSS score is approximately 0.59% (70th percentile), indicating a moderate near-term exploitation probability. There is no current evidence of active in-the-wild exploitation or threat actor attribution, and the vulnerability is not listed in the CISA KEV catalog as of the time of this report (Github Advisory, Feedly).

Exploitation steps

  1. Reconnaissance: Identify systems running terminal-controller-mcp version 0.1.7, which may be exposed via MCP-compatible clients such as Claude Desktop or Cursor. Scan for open MCP server endpoints or review configuration files (e.g., claude_desktop_config.json) if accessible.
  2. Craft malicious payload: Construct a command that bypasses the keyword blacklist by fragmenting the target command using shell substitution. For example, to execute mkfs, use: echo "$($(echo -n m; echo -n k; echo -n f; echo -n s))".
  3. Send crafted MCP request: Submit a tools/call request to the execute_command tool with the malicious payload:
{
  "method": "tools/call",
  "params": {
    "name": "execute_command",
    "arguments": {
      "command": "echo \"$($(echo -n m; echo -n k; echo -n f; echo -n s))\"",
      "timeout": 30
    },
    "_meta": { "progressToken": 23 }
  }
}
  1. Achieve arbitrary command execution: The server passes the input through the insufficient keyword filter and executes it in a shell context. The shell reconstructs and runs the injected command, returning output to the attacker.
  2. Post-exploitation: Use the established execution primitive to exfiltrate data, establish persistence (e.g., add SSH keys, create cron jobs), or pivot to other systems accessible from the server host (GitHub Issue #7).

Indicators of compromise

  • Network: Unexpected inbound MCP protocol requests to the server containing shell metacharacters ($(), ;, |, &) in the command parameter; outbound connections from the MCP server process to unknown external IPs.
  • Logs: MCP server logs showing execute_command calls with obfuscated or fragmented command strings (e.g., echo -n m; echo -n k; echo -n f; echo -n s); repeated failed or unusual command executions in command history (get_command_history).
  • Process: Unexpected child processes spawned by the MCP server Python process (e.g., bash, sh, curl, wget, python, nc); processes running under the MCP server's user account that are unrelated to normal terminal operations.
  • File System: New or modified files in sensitive directories (e.g., ~/.ssh/authorized_keys, /etc/cron.d/, /tmp/); unexpected scripts or binaries created by the MCP server process user (GitHub Issue #7, Github Advisory).

Mitigation and workarounds

The GitHub Advisory (GHSA-h4rf-624j-gj33) lists all versions <= 0.1.7 as affected with no patched version currently published; the repository was archived by the owner on March 3, 2026, indicating the project is no longer maintained. Users should immediately remove or disable terminal-controller-mcp from their MCP client configurations. As interim mitigations: implement network segmentation to restrict access to the MCP server endpoint, monitor for suspicious command execution patterns, and consider replacing the tool with an actively maintained alternative that uses allowlist-based command validation or disables shell interpretation entirely (Github Advisory, Feedly).

Community reactions

The vulnerability received brief coverage from security news aggregators including TheHackerWire on Mastodon and Bluesky shortly after disclosure. Red Hat tracked the CVE and published an advisory entry. No significant vendor statements, in-depth researcher write-ups, or major media coverage have been identified beyond automated vulnerability database entries and social media posts from security news accounts (Red Hat CVE).

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management