Skip to content

v3.8.6 — Security: six advisories, including command execution on the machine running the server

Latest

Choose a tag to compare

@github-actions github-actions released this 08 Oct 08:47
· 2 commits to main since this release

Security release — six advisories fixed. Upgrade: npm install -g mcp-ssh-manager@3.8.6

Advisory Severity What it was
GHSA-759m-wfpq-xmx3 high The default on-error hook pasted the connection error — text a server chooses — into a shell command on the machine running mcp-ssh-manager.
GHSA-rfxw-26h6-7w42 high restricted mode only checked how a command line started.
GHSA-37fv-fcpc-j236 high cwd reached the remote shell unquoted, past the security policy.
GHSA-q37w-vhpx-q5q9 high ssh_db_query evaluated caller-controlled JavaScript on MongoDB.
GHSA-9w6j-vg8f-hp8g medium ssh_db_query accepted a MySQL SELECT … INTO OUTFILE.
GHSA-cwg3-pfmm-w8rm high Host keys were never compared with known_hosts.

Also: ssh_deploy and ssh_backup_schedule quote every value, and a cron schedule must be a schedule.

Thanks to @uozergit, @davutselcuk, @zaara2004 and Francesco Canovi (@TheDarkMist, Black Studio Solutions) for their reports.

Behaviour changes

  • A changed host key is refused, as OpenSSH does. A server reinstalled since its key was recorded needs ssh-keygen -R <host> once. Unknown hosts are still trusted on first use.
  • A restricted allowlist is checked per command: each command in a list or pipeline must match, and the refusal names the one that did not.
  • Hook settings, aliases, the active profile and the logs live in ~/.ssh-manager/, readable by you alone (#87). The package no longer ships a development .hooks-config.json.

Verified: the real upgrade 3.8.5 → 3.8.6 → 3.8.5 keeps all 37 tool schemas and your .env, TOML and environment configuration; every fix has a test that fails without it. Full details in the CHANGELOG.