CVE-2025-9654 Details
Description
A security flaw has been discovered in AiondaDotCom mcp-ssh up to 1.0.3. Affected by this issue is some unknown functionality of the file server-simple.mjs. Performing manipulation results in command injection. The attack can be initiated remotely. Upgrading to version 1.0.4 and 1.1.0 can resolve this issue. The patch is named cd2566a948b696501abfa6c6b03462cac5fb43d8. It is advisable to upgrade the affected component.
A command injection vulnerability has been identified in AiondaDotCom mcp-ssh versions prior to 1.0.4. The issue resides in the file server-simple.mjs, where user-supplied input is improperly handled when constructing SSH commands. This flaw allows remote attackers to inject arbitrary commands, potentially leading to unauthorized command execution on the server.
Users are advised to upgrade to AiondaDotCom mcp-ssh version 1.0.4 or 1.1.0, both of which include the necessary fix for this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 29, 2025CISA-ADP
Assessed Aug 29, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/AiondaDotCom/mcp-ssh/commit/5b9b9c5b28d3f2672f356a790154ed68e17ef453 | [email protected] | Source CodeVendor |
| https://github.com/AiondaDotCom/mcp-ssh/commit/cd2566a948b696501abfa6c6b03462cac5fb43d8 | [email protected] | Source CodeVendor |
| https://vuldb.com/?ctiid.321862 | [email protected] | AdvisoryPermission RequiredRemedy |
| https://vuldb.com/?id.321862 | [email protected] | AdvisoryRemedy |
| https://vuldb.com/?submit.637028 | [email protected] | ExploitTechnical Description |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-74 | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') | [email protected] |
| CWE-77 | Improper Neutralization of Special Elements used in a Command ('Command Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| AiondaDotCom mcp-ssh | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 29, 2025 | New CVE Received | [email protected] |
Volerion