CVE-2025-61492: Gongrzhe Terminal-Controller-Mcp

Critical severity, CVSS 10.0. EPSS: 2.1% chance of exploitation in the next 30 days.

A command injection vulnerability in the execute_command function of terminal-controller-mcp 0.1.7 allows attackers to execute arbitrary commands via a crafted input.

Affected products

  • Gongrzhe Terminal-Controller-Mcp: version 0.1.7 only

Published 2026-01-07. Last modified 2026-06-17.