xcode-mcp-server@1.0.2 vulnerabilities

An MCP server for Xcode integration, enabling AI assistants to interact with Xcode projects

Direct Vulnerabilities

Known vulnerabilities in the xcode-mcp-server package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • M
Arbitrary Command Injection

xcode-mcp-server is an An MCP server for Xcode integration, enabling AI assistants to interact with Xcode projects

Affected versions of this package are vulnerable to Arbitrary Command Injection via the registerXcodeTools function in the run_lldb component when processing the args argument. An attacker can execute arbitrary system commands by supplying crafted input remotely.

How to fix Arbitrary Command Injection?

A fix was pushed into the master branch but not yet published.

*