Security: AiondaDotCom/mcp-ssh
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
SSH config poisoning via downloadFile turns remote command execution into local RCEGHSA-pj6m-cx2p-44gh published
Aug 10, 2026 by ferraroHigh -
SCP Remote-Spec Host Allowlist Bypass via `localPath` in `downloadFile`GHSA-gpr2-2wqr-7rgp published
Aug 10, 2026 by ferraroHigh -
SSH/SCP option injection allowing local RCE in @aiondadotcom/mcp-sshGHSA-p4h8-56qp-hpgv published
Apr 11, 2026 by ferraroHigh
Learn more about advisories related to AiondaDotCom/mcp-ssh in the GitHub Advisory Database