GHSA-8jx2-rhfh-q928
godot-mcp has Command Injection via unsanitized projectPath
Quick fix
GHSA-8jx2-rhfh-q928 — @coding-solo/godot-mcp: upgrade to the fixed version with the command below.
npm install @coding-solo/godot-mcp@0.1.1Details
### Impact A Command Injection vulnerability in godot-mcp allows remote code execution. The `executeOperation` function passed user-controlled input (e.g., `projectPath`) directly to `exec()`, which spawns a shell. An attacker could inject shell metacharacters like `$(command)` or `&calc` to execute arbitrary commands with the privileges of the MCP server process.
This affects any tool that accepts `projectPath`, including `create_scene`, `add_node`, `load_sprite`, and others.
### Patches Fixed in version 0.1.1 by switching from `exec()` to `execFile()`, which does not invoke a shell.
### Workarounds None. Users should upgrade immediately.
### Resources - https://github.com/Coding-Solo/godot-mcp/issues/64 - https://github.com/Coding-Solo/godot-mcp/pull/67
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 0.1.1npm install @coding-solo/godot-mcp@0.1.1References
- https://github.com/Coding-Solo/godot-mcp/security/advisories/GHSA-8jx2-rhfh-q928[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2026-25546[ADVISORY]
- https://github.com/Coding-Solo/godot-mcp/issues/64[WEB]
- https://github.com/Coding-Solo/godot-mcp/pull/67[WEB]
- https://github.com/Coding-Solo/godot-mcp/commit/21c785d923cfdb471ea60323c13807d62dfecc5a[WEB]
- https://github.com/Coding-Solo/godot-mcp[PACKAGE]