Junglewise Threat Intelligence

profullstack mcp-server OS command injection in domain_lookup

Severity: low · CVSS 3.1 · Published 2026-05-09

Technologies: Profullstack Mcp Server. Vendors: npm.

Executive brief

The mcp-server package provides domain lookup functionality for checking domain availability. An unauthenticated attacker can inject arbitrary shell commands through the domain lookup API endpoints, allowing complete remote code execution on the server with full read/write file access and potential for credential theft or lateral movement.

Technical details

This vulnerability is a classic OS command injection (CWE-78) in the domain_lookup module. The vulnerable code directly concatenates user-supplied domains or keywords into a shell command string without quoting, escaping, or validation, then executes it via child_process.execAsync(). Both POST /domain-lookup/check and POST /domain-lookup/bulk endpoints are affected. No authentication is enforced and the server binds to 0.0.0.0 by default. An attacker can inject shell metacharacters (semicolons, pipes, command substitution) to execute arbitrary commands as the server process UID. Proof-of-concept exploits have been demonstrated on versions ≤1.4.12; the fix in 1.5.0 replaces execAsync with execFile/spawn using argument arrays, eliminates shell interpretation, and adds input validation.

Affected products

  • profullstack mcp-server <=1.4.12

Timeline

  • 2026-05-09: disclosed
  • 2026-05-09: patched: Version 1.5.0 released with fix

References