CVE-2025-54994
📛 CVE Title
@akoskm/create-mcp-server-stdio has Command Injection in MCP Server due to unsafe `exec` API
Description
@akoskm/create-mcp-server-stdio is an MCP server starter kit that uses the StdioServerTransport. Prior to version 0.0.13, the MCP Server is written in a way that is vulnerable to command injection vulnerability attacks as part of some of its MCP Server tool definition and implementation. The MCP Server exposes the tool `which-app-on-port` which relies on Node.js child process API `exec` which is an unsafe and vulnerable API if concatenated with untrusted user input. Version 0.0.13 contains a fix for the issue.
Overview
- State
- PUBLISHED
- Assigner (CNA)
- GitHub_M
- CVSS severity
- CRITICAL
- CVSS score
- 9.3 / 10
- CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N- Effective score
- 9.3 / 10 CRITICAL source: CNA overview
- CWE(s)
-
CWE-78 - Reserved
- 2025-08-04
- Published
- 2025-09-08 21:37 UTC
- Last updated
- 2025-09-08 21:53 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2025/54xxx/CVE-2025-54994.json
- Linked Threat
- CVE-2025-54994 — @akoskm/create-mcp-server-stdio has Command Injection in MCP Server due to unsafe `exec` API
NVD triage scoring NVD CVE 2.0
Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.
- NVD published
- 2025-09-08 20:15:35 UTC
- NVD last modified
- 2026-06-17 09:41:04 UTC
- EPSS score
- 0.0137 (probability of exploitation in next 30 days)
- EPSS percentile
- 69.30% vs all CVEs — higher = more likely to be exploited, as of 2026-08-06
NVD / KEV / EPSS data refreshed 2026-08-06 23:03 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2025-27167 - Assigner
- GitHub_M
- Published
- Sep 8, 2025, 7:37:42 PM
- Updated
- Sep 8, 2025, 7:53:45 PM
- EUVD base score (CVSS 4.0)
-
9.3 / 10
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N - EUVD-reported EPSS
- 0.4400
- Vendors
- akoskm
- Products
-
create-mcp-server-stdio (< 0.0.13)
- Aliases
-
GHSA-3ch2-jxxc-v4xf
ENISA description: @akoskm/create-mcp-server-stdio is an MCP server starter kit that uses the StdioServerTransport. Prior to version 0.0.13, the MCP Server is written in a way that is vulnerable to command injection vulnerability attacks as part of some of its MCP Server tool definition and implementation. The MCP Server exposes the tool `which-app-on-port` which relies on Node.js child process API `exec` which is an unsafe and vulnerable API if concatenated with untrusted user input. Version 0.0.13 contains a fix for the issue.
Affected products (1)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| akoskm | create-mcp-server-stdio |
< 0.0.13 (affected)
|
— |
Vendor references (3)
References embedded in the original CVE record by the assigning CNA.
- https://github.com/akoskm/create-mcp-server-stdio/security/advisories/GHSA-3ch2-jxxc-v4xf x_refsource_CONFIRM
- https://github.com/akoskm/create-mcp-server-stdio/commit/48c26bbe1f8c62764e4592f33c8300d1cadd2eac x_refsource_MISC
- https://github.com/akoskm/create-mcp-server-stdio/blob/main/src/index.ts#L24-L40 x_refsource_MISC
Web references (0)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
No web references attached yet.
NVD-tagged references (3)
Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.
- https://github.com/akoskm/create-mcp-server-stdio/blob/main/src/index.ts#L24-L40 security-advisories@github.com
- https://github.com/akoskm/create-mcp-server-stdio/commit/48c26bbe1f8c62764e4592f33c8300d1cadd2eac security-advisories@github.com
- https://github.com/akoskm/create-mcp-server-stdio/security/advisories/GHSA-3ch2-jxxc-v4xf security-advisories@github.com
Indicators (1)
IOCs linked to the auto-promoted Threat row.
| Type | Value | VirusTotal | Attached |
|---|---|---|---|
| domain |
node.js
|
no local data | 2026-05-18 21:19 UTC |
Remediations (25)
Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.
-
web:nvd.nist.gov
Description Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lua script to manipulate the garbage collector, trigger a use-after-free and potentially lead to remote code execution. The problem exists in all versions of Redis with Lua scripting. This issue is fixed in version 8.2.2. To workaround ...
2026-09-24 06:26 UTC -
web:www.microsoft.com
Help protect your computing environment by keeping up to date on Microsoft technical security notifications. Security Update Guide Notifications Microsoft's free Security Update Guide Notifications provide links to security-related software updates and notification of re-released security updates. These notifications are sent via email throughout the month as needed. You can choose the type of ...
2026-09-24 06:26 UTC -
web:blog.talosintelligence.com
Microsoft has released its monthly security update for February 2026, which includes 55 vulnerabilities affecting a range of products, including one ( CVE - 2025 -59498) that Microsoft marked as "Critical".
2026-09-24 06:26 UTC -
web:support.microsoft.com
This Hotpatch update for Windows 11, version 25H2 and 24H2 (KB5079420), improves functionality, performance, and reliability. To learn more about differences between security updates, optional non-security preview updates, out-of-band (OOB) updates, and continuous innovation, see Windows monthly updates explained. For information on Windows update terminology, see the different types of ...
2026-09-24 06:26 UTC -
web:feedly.com
On October 15, NSFOCUS CERT detected that Microsoft released the October Security Update patch , fixing 175 security issues involving widely used products such as Windows, Microsoft Office, Azure, Apps, Microsoft Exchange Server, and Microsoft Visual Studio. Windows Server Update Services Remote Code Execution Vulnerability ( CVE - 2025 -59287):
2026-09-24 06:26 UTC -
web:support.microsoft.com
This Hotpatch update for Windows 11, version 25H2 and 24H2 (KB5120994) includes security improvements. To learn more about differences between security updates, optional non-security preview updates, out-of-band (OOB) updates, and continuous innovation, see Windows monthly updates explained. For information on Windows update terminology, see the different types of Windows software updates. To ...
2026-09-24 06:26 UTC -
web:msrc.microsoft.com
The Microsoft Security Response Center (MSRC) investigates all reports of security vulnerabilities affecting Microsoft products and services, and provides the information here as part of the ongoing effort to help you manage security risks and help keep your systems protected.
2026-09-24 06:26 UTC -
web:senserva.com
Every Microsoft security patch (KB) and the CVEs it fixes, with severity, CVSS, and CISA KEV status. Cross-linked to the CVE reference.
2026-09-24 06:26 UTC -
web:attack.mitre.org
This mitigation can be implemented through the following measures: Regular Operating System Updates Implementation: Apply the latest Windows security updates monthly using WSUS (Windows Server Update Services) or a similar patch management solution. Configure systems to check for updates automatically and schedule reboots during maintenance ...
2026-05-22 14:34 UTC -
web:support.microsoft.com
Applies To SQL Server 2025 on Windows (all editions), SQL Server 2025 on Linux (all editions) Summary Improvements and fixes included in this update How to obtain and install the update How to obtain or download the latest cumulative update package for Linux More information File information Information about protection and security Summary This security update contains fixes and resolves ...
2026-05-22 14:34 UTC -
web:winbuzzer.com
Microsoft's September 2025 Patch Tuesday addresses 81 vulnerabilities, including two zero-day flaws in SMB and SQL Server, plus critical NTLM & Office updates.
2026-05-22 14:34 UTC -
web:www.csa.gov.sg
7 August 2025 Trend Micro has released a mitigation tool addressing critical vulnerabilities in its endpoint security products. Users and administrators are advised to apply the FixTool as a short-term mitigation measure.
2026-05-22 14:34 UTC -
web:www.msn.com
Microsoft suggests the threat is being used in phishing attacks against vulnerable systems since successful exploitation requires local access to the PC.
2026-05-22 14:34 UTC -
web:www.rapid7.com
Microsoft is addressing 176 vulnerabilities this September 2025 Patch Tuesday, which is a lot. This includes a zero-day denial of service vulnerability in SQL Server.
2026-05-22 14:34 UTC -
web:www.tenable.com
Trend Micro releases a temporary mitigation tool to reduce exposure to two unpatched zero-day command injection vulnerabilities which have been exploited.
2026-05-22 14:34 UTC -
web:www.bleepingcomputer.com
Microsoft says customers in restricted network environments may encounter Windows Update failures after installing the January 2026 optional non-security preview updates.
2026-05-22 02:56 UTC -
web:www.computerworld.com
Each month, the team at Readiness analyzes the latest Patch Tuesday updates from Microsoft and provides detailed, actionable testing guidance. The company's Patch Tuesday release for February ...
2026-05-22 02:56 UTC -
web:www.rapid7.com
Microsoft has published 172 new vulnerabilities, including six zero-day vulnerabilities. Windows 10 moves past the end of support, sort of. Critical RCE in Windows Server Update Service.
2026-05-22 02:56 UTC -
web:betanews.com
Another month, another update for Windows which is problematic. This time around, it is the May 2026 Windows 11 security update - or the KB5089549 update.
2026-05-22 02:56 UTC -
web:nvd.nist.gov
Official websites use .gov A .gov website belongs to an official government organization in the United States.
2026-05-22 02:56 UTC -
web:msrc.microsoft.com
The Microsoft Security Response Center (MSRC) investigates all reports of security vulnerabilities affecting Microsoft products and services, and provides the information here as part of the ongoing effort to help you manage security risks and help keep your systems protected.
2026-05-22 02:56 UTC -
web:krebsonsecurity.com
Microsoft Corp. today issued security updates to fix more than 80 vulnerabilities in its Windows operating systems and software. There are no known "zero-day" or actively exploited vulnerabilities ...
2026-05-22 02:56 UTC -
web:dailysecurityreview.com
Redis Releases Update to Fix CVE - 2025 -49844 Critical RCE Vulnerability A critical use-after-free vulnerability in Redis ( CVE - 2025 -49844) enables remote code execution via Lua scripting. Affecting all versions up to 8.2.1, the flaw is already being exploited in the wild, prompting urgent patching and mitigation calls from major security vendors.
2026-05-22 02:56 UTC -
web:zecurit.com
Get the complete breakdown of Microsoft's May 2026 Patch Tuesday. We analyze the latest security updates and all critical CVEs .
2026-05-22 02:56 UTC -
web:www.ninjaone.com
Overview KB5087054 is a cumulative security and reliability update for the .NET Framework targeting Windows 11 version 24H2 systems. Released on May 12, 2026, this patch addresses critical vulnerabilities affecting both .NET Framework 3.5 and 4.8.1 installations. The update is designed to be deployed as part of standard maintenance routines and is available through multiple distribution ...
2026-05-22 02:56 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2025-54994.json.
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2025-54994",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-09-08T19:53:37.664700Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2025-09-08T19:53:45.662Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "create-mcp-server-stdio",
"vendor": "akoskm",
"versions": [
{
"status": "affected",
"version": "< 0.0.13"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "@akoskm/create-mcp-server-stdio is an MCP server starter kit that uses the StdioServerTransport. Prior to version 0.0.13, the MCP Server is written in a way that is vulnerable to command injection vulnerability attacks as part of some of its MCP Server tool definition and implementation. The MCP Server exposes the tool `which-app-on-port` which relies on Node.js child process API `exec` which is an unsafe and vulnerable API if concatenated with untrusted user input. Version 0.0.13 contains a fix for the issue."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 9.3,
"baseSeverity": "CRITICAL",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-78",
"description": "CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2025-09-08T19:37:42.667Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/akoskm/create-mcp-server-stdio/security/advisories/GHSA-3ch2-jxxc-v4xf",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/akoskm/create-mcp-server-stdio/security/advisories/GHSA-3ch2-jxxc-v4xf"
},
{
"name": "https://github.com/akoskm/create-mcp-server-stdio/commit/48c26bbe1f8c62764e4592f33c8300d1cadd2eac",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/akoskm/create-mcp-server-stdio/commit/48c26bbe1f8c62764e4592f33c8300d1cadd2eac"
},
{
"name": "https://github.com/akoskm/create-mcp-server-stdio/blob/main/src/index.ts#L24-L40",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/akoskm/create-mcp-server-stdio/blob/main/src/index.ts#L24-L40"
}
],
"source": {
"advisory": "GHSA-3ch2-jxxc-v4xf",
"discovery": "UNKNOWN"
},
"title": "@akoskm/create-mcp-server-stdio has Command Injection in MCP Server due to unsafe `exec` API"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2025-54994",
"datePublished": "2025-09-08T19:37:42.667Z",
"dateReserved": "2025-08-04T17:34:24.420Z",
"dateUpdated": "2025-09-08T19:53:45.662Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}