mcp-package-docs@0.1.21 vulnerabilities

An MCP server that provides LLMs with efficient access to package documentation across multiple programming languages

  • latest version

    0.1.28

  • latest non vulnerable version

  • first published

    7 months ago

  • latest version published

    25 days ago

  • deprecated

    Package is deprecated

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the mcp-package-docs package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Arbitrary Command Injection

    mcp-package-docs is an An MCP server that provides LLMs with efficient access to package documentation across multiple programming languages

    Affected versions of this package are vulnerable to Arbitrary Command Injection via unsanitized input passed to the exec function. An attacker can execute arbitrary system commands by injecting shell metacharacters into input parameters that are incorporated directly into shell command strings.

    How to fix Arbitrary Command Injection?

    Upgrade mcp-package-docs to version 0.1.28 or higher.

    <0.1.28