mcp-server-semgrep@1.0.0

MCP Server for Semgrep Integration - static code analysis with AI

  • latest version

    1.0.1

  • latest non vulnerable version

  • first published

    10 months ago

  • latest version published

    1 months ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the mcp-server-semgrep package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Arbitrary Command Injection

    mcp-server-semgrep is a MCP Server for Semgrep Integration - static code analysis with AI

    Affected versions of this package are vulnerable to Arbitrary Command Injection via the analyze_results, filter_results, export_results, compare_results, scan_directory, or create_rule functions in the MCP Interface component when processing the ID argument. An attacker can execute arbitrary operating system commands by supplying crafted input remotely.

    How to fix Arbitrary Command Injection?

    Upgrade mcp-server-semgrep to version 1.0.1 or higher.

    <1.0.1