Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-h4rf-624j-gj33 | terminal-controller-mcp vulnerable to Command Injection |
Fri, 30 Jan 2026 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gongrzhe
Gongrzhe terminal-controller-mcp |
|
| CPEs | cpe:2.3:a:gongrzhe:terminal-controller-mcp:0.1.7:*:*:*:*:*:*:* | |
| Vendors & Products |
Gongrzhe
Gongrzhe terminal-controller-mcp |
Wed, 07 Jan 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-77 | |
| Metrics |
cvssV3_1
|
Wed, 07 Jan 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A command injection vulnerability in the execute_command function of terminal-controller-mcp 0.1.7 allows attackers to execute arbitrary commands via a crafted input. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-01-07T19:14:01.084Z
Reserved: 2025-09-26T00:00:00.000Z
Link: CVE-2025-61492
Updated: 2026-01-07T19:13:24.515Z
Status : Analyzed
Published: 2026-01-07T18:15:51.117
Modified: 2026-01-30T01:40:38.973
Link: CVE-2025-61492
No data.
OpenCVE Enrichment
No data.
Github GHSA