@profullstack/mcp-server@1.4.4

A generic, modular server for implementing the Model Context Protocol (MCP)

  • latest version

    1.4.12

  • first published

    11 months ago

  • latest version published

    11 months ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the @profullstack/mcp-server package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • C
    Command Injection

    @profullstack/mcp-server is an A generic, modular server for implementing the Model Context Protocol (MCP)

    Affected versions of this package are vulnerable to Command Injection via the domain_lookup process. An attacker can execute arbitrary operating system commands with the privileges of the server process by sending crafted input to the exposed HTTP endpoints, which is concatenated into a shell command without proper sanitization.

    How to fix Command Injection?

    There is no fixed version for @profullstack/mcp-server.

    *