Junglewise Threat Intelligence

mcp-ssh-tool file transfer path policy bypass

Severity: medium · CVSS 4 · Published 2026-05-07

Vendors: npm.

Executive brief

mcp-ssh-tool is a Node.js library that provides SSH functionality for remote command execution and file operations. Two security issues were discovered: insufficient validation of file transfer paths could allow attackers to access files outside intended directories, and bearer token authentication uses non-constant-time comparison making it vulnerable to timing attacks. These weaknesses could lead to unauthorized file access or authentication bypass in HTTP-deployed instances.

Technical details

The vulnerability consists of two separate issues: (1) insufficient local path policy enforcement in file transfer handling with incomplete canonicalization and segment-boundary validation allowing bypass of deny-prefix path policies (CWE-22: improper limitation of a pathname to a restricted directory), and (2) non-constant-time comparison of HTTP bearer tokens enabling a timing side-channel attack (CWE-208). The issues affect versions prior to 2.1.1 and are exploitable over the network for HTTP deployments when MCP clients have transfer capabilities enabled. Patch available in version 2.1.1 and later.

Affected products

  • oaslananka mcp-ssh-tool < 2.1.1

Timeline

  • 2026-05-07: disclosed: Advisory GHSA-j7h9-2jh7-g967 published
  • 2026-05-07: patched: Version 2.1.1 released with security hardening

References

Related threats