VDB
Sign up
HIGH7.8

GHSA-8jx2-rhfh-q928

godot-mcp has Command Injection via unsanitized projectPath

Quick fix

GHSA-8jx2-rhfh-q928 — @coding-solo/godot-mcp: upgrade to the fixed version with the command below.

npm install @coding-solo/godot-mcp@0.1.1

Details

### Impact A Command Injection vulnerability in godot-mcp allows remote code execution. The `executeOperation` function passed user-controlled input (e.g., `projectPath`) directly to `exec()`, which spawns a shell. An attacker could inject shell metacharacters like `$(command)` or `&calc` to execute arbitrary commands with the privileges of the MCP server process.

This affects any tool that accepts `projectPath`, including `create_scene`, `add_node`, `load_sprite`, and others.

### Patches Fixed in version 0.1.1 by switching from `exec()` to `execFile()`, which does not invoke a shell.

### Workarounds None. Users should upgrade immediately.

### Resources - https://github.com/Coding-Solo/godot-mcp/issues/64 - https://github.com/Coding-Solo/godot-mcp/pull/67

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@coding-solo/godot-mcp
Introduced in: 0Fixed in: 0.1.1
Fixnpm install @coding-solo/godot-mcp@0.1.1

References