-
Notifications
You must be signed in to change notification settings - Fork 1
Labels
P1Important priorityImportant priorityepicMilestone-level tracking issueMilestone-level tracking issuemcpMCP client/serverMCP client/serversecuritySecurity hardeningSecurity hardening
Description
Summary
MCP server commands from config are executed without validation. Config tampering leads to arbitrary code execution.
Child Issues
- Validate MCP server command against allowlist #651 Validate MCP server command against allowlist
- Restrict MCP env var injection to safe subset #652 Restrict MCP env var injection to safe subset
Reactions are currently unavailable
Sub-issues
Metadata
Metadata
Assignees
Labels
P1Important priorityImportant priorityepicMilestone-level tracking issueMilestone-level tracking issuemcpMCP client/serverMCP client/serversecuritySecurity hardeningSecurity hardening