VDB
Sign up
HIGH

GHSA-j7h9-2jh7-g967

mcp-ssh-tool has file transfer path policy bypass and bearer token comparison hardening

Quick fix

GHSA-j7h9-2jh7-g967 — mcp-ssh-tool: upgrade to the fixed version with the command below.

npm install mcp-ssh-tool@2.1.1

Details

## Summary

`mcp-ssh-tool` has released version `2.1.1` with security hardening for transfer path authorization and HTTP bearer authentication.

The release addresses:

- insufficient local path policy enforcement in transfer-related filesystem handling - incomplete canonicalization and segment-boundary handling for deny-prefix path policy checks - non-constant-time HTTP bearer token comparison

## Impact

Affected versions may allow policy bypass in transfer path handling under specific configurations, and may expose a timing side channel in bearer-token comparison for HTTP deployments.

## Patched Version

Upgrade to `mcp-ssh-tool >= 2.1.1`.

```bash npm install -g mcp-ssh-tool@latest ```

## Workarounds

For deployments that cannot immediately upgrade:

- avoid exposing HTTP transport beyond loopback - use strict filesystem policy configuration - avoid granting MCP clients access to sensitive local transfer paths - monitor audit logs for unexpected transfer operations

## Credits

Reported by `dodge1218`.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/mcp-ssh-tool
Introduced in: 0Fixed in: 2.1.1
Fixnpm install mcp-ssh-tool@2.1.1

References