Repository navigation
v3.8.6 — Security: six advisories, including command execution on the machine running the server
LatestSecurity release — six advisories fixed. Upgrade: npm install -g mcp-ssh-manager@3.8.6
| Advisory | Severity | What it was |
|---|---|---|
| GHSA-759m-wfpq-xmx3 | high | The default on-error hook pasted the connection error — text a server chooses — into a shell command on the machine running mcp-ssh-manager. |
| GHSA-rfxw-26h6-7w42 | high | restricted mode only checked how a command line started. |
| GHSA-37fv-fcpc-j236 | high | cwd reached the remote shell unquoted, past the security policy. |
| GHSA-q37w-vhpx-q5q9 | high | ssh_db_query evaluated caller-controlled JavaScript on MongoDB. |
| GHSA-9w6j-vg8f-hp8g | medium | ssh_db_query accepted a MySQL SELECT … INTO OUTFILE. |
| GHSA-cwg3-pfmm-w8rm | high | Host keys were never compared with known_hosts. |
Also: ssh_deploy and ssh_backup_schedule quote every value, and a cron schedule must be a schedule.
Thanks to @uozergit, @davutselcuk, @zaara2004 and Francesco Canovi (@TheDarkMist, Black Studio Solutions) for their reports.
Behaviour changes
- A changed host key is refused, as OpenSSH does. A server reinstalled since its key was recorded needs
ssh-keygen -R <host>once. Unknown hosts are still trusted on first use. - A
restrictedallowlist is checked per command: each command in a list or pipeline must match, and the refusal names the one that did not. - Hook settings, aliases, the active profile and the logs live in
~/.ssh-manager/, readable by you alone (#87). The package no longer ships a development.hooks-config.json.
Verified: the real upgrade 3.8.5 → 3.8.6 → 3.8.5 keeps all 37 tool schemas and your .env, TOML and environment configuration; every fix has a test that fails without it. Full details in the CHANGELOG.