Executive brief
mcp-maigret is an open-source tool used for OSINT research to gather user account information from public sources. A flaw in how it processes usernames allows an attacker to inject shell commands and execute arbitrary code on the system running the tool. An attacker can exploit this remotely without authentication to gain control of the system or steal sensitive data collected during searches.
Technical details
The vulnerability is a classic command injection flaw (CWE-74, CWE-77) in the search_username functionality of src/index.ts. The root cause is unsafe use of exec() with concatenated user input, which allows shell metacharacters in the username parameter to break out of the intended command context. The attack vector is network-based with no authentication or user interaction required. An attacker can craft a malicious username string containing shell metacharacters (e.g., `; rm -rf /`) to execute arbitrary system commands. The fix, released in version 1.0.13 (commit b1ae073c), replaces exec() with execFile(), adds strict input validation (alphanumeric, underscore, hyphen, period only for usernames), and passes Docker command arguments as arrays instead of concatenated strings.
Affected products
- BurtTheCoder mcp-maigret up to 1.0.12
Timeline
- 2026-02-08: disclosed
- 2026-01-27: patched: Fix released in version 1.0.13
References
- https://github.com/BurtTheCoder/mcp-maigret/issues/9
- https://github.com/BurtTheCoder/mcp-maigret/pull/10
- https://github.com/BurtTheCoder/mcp-maigret/commit/b1ae073c4b3e789ab8de36dc6ca8111ae9399e7a
- https://github.com/BurtTheCoder/mcp-maigret
- https://github.com/BurtTheCoder/mcp-maigret/releases/tag/v1.0.13
- https://vuldb.com/?ctiid.344765