Executive brief
mcp-ssh-tool is a utility for managing remote file transfers and SSH operations. The tool contains two security flaws: insufficient validation of file transfer paths that could allow an attacker to bypass access restrictions and read/write unauthorized files, and a timing-based weakness in HTTP bearer token authentication that could leak credential information. These vulnerabilities affect all versions prior to 2.1.1.
Technical details
The vulnerability comprises two distinct flaws: (1) Path traversal due to CWE-22 (Improper Limitation of a Pathname to a Restricted Directory) in file transfer operations, caused by insufficient local path policy enforcement and incomplete canonicalization/segment-boundary handling for deny-prefix path policy checks, allowing bypass of configured access restrictions; and (2) Timing side-channel due to CWE-208 (Observable Timing Discrepancy) in HTTP bearer token comparison, using non-constant-time string comparison that leaks information about valid authentication tokens. The path policy bypass affects transfer-related filesystem handling under specific configurations. The bearer token timing vulnerability is relevant only in HTTP deployments. Both require no privileges or user interaction, attack complexity is low, and network-based exploitation is possible. Patch available in version 2.1.1 and later.
Affected products
- mcp-ssh-tool mcp-ssh-tool <= 2.1.0
Timeline
- 2026-05-07: disclosed: Advisory published to GitHub Advisory Database
- 2026-05-07: patched: Patched version 2.1.1 released