Vulnerabilities/

mcp-package-docs vulnerable to command injection in several tools

Severity:
High

Description

A command injection vulnerability exists in the mcp-package-docs MCP Server. The vulnerability is caused by the unsanitized use of input parameters within a call to child_process.exec, enabling an attacker to inject arbitrary system commands. Successful exploitation can lead to remote code execution under the server process’s privileges.

Recommendation

Update the mcp-package-docs package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
mcp-package-docs
Anything's wrong? Let us know Last updated on August 05, 2025