node-code-sandbox-mcp@1.0.1 vulnerabilities

Run arbitrary JavaScript inside disposable Docker containers and install npm dependencies on the fly.

Direct Vulnerabilities

Known vulnerabilities in the node-code-sandbox-mcp package. This does not include vulnerabilities belonging to this package’s dependencies.

How to fix?

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

Fix for free
VulnerabilityVulnerable Version
  • C
Arbitrary Command Injection

node-code-sandbox-mcp is a Run arbitrary JavaScript inside disposable Docker containers and install npm dependencies on the fly.

Affected versions of this package are vulnerable to Arbitrary Command Injection via the child_process.execSync function. An attacker can execute arbitrary system commands on the host machine by supplying crafted input parameters, which are not properly sanitized.

How to fix Arbitrary Command Injection?

Upgrade node-code-sandbox-mcp to version 1.3.0 or higher.

<1.3.0