Executive brief
The @akoskm/create-mcp-server-stdio package, a starter kit for building Model Context Protocol (MCP) servers, is vulnerable to command injection. This flaw allows an attacker to execute arbitrary system commands on the host machine by providing malicious input to the 'which-app-on-port' tool. In practice, this could lead to full system compromise, unauthorized data access, or service disruption, especially if the server is triggered by an AI model processing untrusted prompts.
Technical details
The vulnerability exists in the 'which-app-on-port' tool implementation within the MCP server. The code uses the Node.js child_process.exec() function to run shell commands (lsof and ps) by concatenating them with user-supplied port numbers without proper sanitization. An attacker can exploit this by injecting shell metacharacters (e.g., semicolons or pipes) into the port parameter. This is particularly dangerous in MCP environments where Large Language Models (LLMs) might be manipulated via prompt injection to call this tool with malicious payloads. The issue was resolved in version 0.0.13 by migrating from exec() to execFile(), which handles arguments more securely.
Affected products
- akoskm @akoskm/create-mcp-server-stdio <= 0.0.13
Timeline
- 2025-07-12: disclosed: Vulnerability reported and fix proposed via pull request.
- 2025-07-14: patched: Fix merged into main branch.
- 2025-09-08: advisory: GitHub Security Advisory published.
References
- https://github.com/akoskm/create-mcp-server-stdio/security/advisories/GHSA-3ch2-jxxc-v4xf
- https://github.com/akoskm/create-mcp-server-stdio/pull/1
- https://github.com/akoskm/create-mcp-server-stdio/commit/48c26bbe1f8c62764e4592f33c8300d1cadd2eac
- https://github.com/akoskm/create-mcp-server-stdio
- https://github.com/akoskm/create-mcp-server-stdio/blob/main/src/index.ts