Skip to content

fix(mcp): prevent shell command injection in ScriptNotifier (fixes #99) - #144

Open
Mahesh-Abeykoon wants to merge 1 commit into
google:mainfrom
Mahesh-Abeykoon:fix/script-notifier-command-injection
Open

Mahesh-Abeykoon wants to merge 1 commit into
google:mainfrom
Mahesh-Abeykoon:fix/script-notifier-command-injection

Conversation

@Mahesh-Abeykoon

Copy link
Copy Markdown

Summary

Fixes #99 by preventing arbitrary shell command injection in ScriptNotifier.

Problem

In mcp_server/notifiers/script.py, ScriptNotifier.send() formatted the user-configured command template ARTEMIS_NOTIFY_CMD using naive string replacement:

cmd = self._cmd_template.replace("{title}", title).replace("{message}", message)
subprocess.run(cmd, shell=True, check=True)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Shell command injection in ScriptNotifier via unescaped {message}/{title} template substitution (ARTEMIS_NOTIFY_CMD)

1 participant