U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2025-54073

Change History

New CVE Received from GitHub, Inc. 7/18/2025 12:15:30 PM

Action Type Old Value New Value
Added Description

								
							
							
						
mcp-package-docs is an MCP (Model Context Protocol) server that provides LLMs with efficient access to package documentation across multiple programming languages and language server protocol (LSP) capabilities. A command injection vulnerability exists in the `mcp-package-docs` MCP Server prior to the fix in commit cb4ad49615275379fd6f2f1cf1ec4731eec56eb9. The vulnerability is caused by the unsanitized use of input parameters within a call to `child_process.exec`, enabling an attacker to inject arbitrary system commands. Successful exploitation can lead to remote code execution under the server process's privileges. The server constructs and executes shell commands using unvalidated user input directly within command-line strings. This introduces the possibility of shell metacharacter injection (`|`, `>`, `&&`, etc.). Commit cb4ad49615275379fd6f2f1cf1ec4731eec56eb9 in version 0.1.27 contains a fix for the issue, but upgrading to 0.1.28 is recommended.
Added CVSS V3.1

								
							
							
						
AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Added CWE

								
							
							
						
CWE-77
Added Reference

								
							
							
						
https://equixly.com/blog/2025/03/29/mcp-server-new-security-nightmare
Added Reference

								
							
							
						
https://github.com/advisories/GHSA-3q26-f695-pp76
Added Reference

								
							
							
						
https://github.com/advisories/GHSA-5w57-2ccq-8w95
Added Reference

								
							
							
						
https://github.com/advisories/GHSA-gjv4-ghm7-q58q
Added Reference

								
							
							
						
https://github.com/sammcj/mcp-package-docs/commit/cb4ad49615275379fd6f2f1cf1ec4731eec56eb9
Added Reference

								
							
							
						
https://github.com/sammcj/mcp-package-docs/releases/tag/v0.1.27
Added Reference

								
							
							
						
https://github.com/sammcj/mcp-package-docs/releases/tag/v0.1.28
Added Reference

								
							
							
						
https://github.com/sammcj/mcp-package-docs/security/advisories/GHSA-vf9j-h32g-2764
Added Reference

								
							
							
						
https://invariantlabs.ai/blog/mcp-github-vulnerability