CVE-2025-66401: Kapilduraphe Mcp Watch
Critical severity, CVSS 9.8. EPSS: 2.2% chance of exploitation in the next 30 days.
MCP Watch is a comprehensive security scanner for Model Context Protocol (MCP) servers. In 0.1.2 and earlier, the MCPScanner class contains a critical Command Injection vulnerability in the cloneRepo method. The application passes the user-supplied githubUrl argument directly to a system shell via execSync without sanitization. This allows an attacker to execute arbitrary commands on the host machine by appending shell metacharacters to the URL.
Affected products
- Kapilduraphe Mcp Watch: up to and including 0.1.2
Published 2025-12-01. Last modified 2026-06-17.