In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsThere is no fixed version for @profullstack/mcp-server.
@profullstack/mcp-server is an A generic, modular server for implementing the Model Context Protocol (MCP)
Affected versions of this package are vulnerable to Command Injection via the domain_lookup process. An attacker can execute arbitrary operating system commands with the privileges of the server process by sending crafted input to the exposed HTTP endpoints, which is concatenated into a shell command without proper sanitization.