Junglewise Threat Intelligence

CVE-2025-59834: adb-mcp command injection in inspect_ui tool

CVE-2025-59834 · Severity: low · CVSS 3.1 · Published 2025-09-24

Vendors: npm.

Executive brief

adb-mcp is an MCP server that allows AI assistants like Claude and Cursor to interact with Android devices via ADB commands. The inspect_ui tool is vulnerable to command injection because it concatenates user-supplied device arguments directly into shell commands without sanitization. An attacker can trick the AI assistant through prompt injection to pass malicious shell metacharacters (e.g., `;rm -rf /;#`) that would execute arbitrary commands on the server host with the privileges of the MCP process.

Technical details

The vulnerability is a classic OS command injection (CWE-78) in the adb-mcp MCP server's inspect_ui tool. The tool accepts user input for the device argument and passes it directly to the Node.js child_process.exec() API via string concatenation in commands like `adb ${deviceArg}shell uiautomator dump ...`. The exec() function is inherently unsafe for untrusted input because it spawns a shell that interprets metacharacters. An attacker exploiting this through prompt injection can inject shell metacharacters (e.g., `;`, `&`, `|`, `$(...)`) to execute arbitrary commands on the host running the MCP server. The vulnerability requires network access to the MCP server and the ability to manipulate the LLM's tool invocation (no authentication or privileged context required), but execution context is typically the MCP server process user. The fix is to replace exec() with execFile() and pass arguments as an array instead of a concatenated string.

Affected products

  • srmorete adb-mcp <=0.1.0

Timeline

  • 2025-09-24: disclosed: GHSA-54j7-grvr-9xwg published
  • 2025-09-24: patched: Security patch merged in commit 041729c

References