Skip to content

Conversation

@davidfirst
Copy link
Member

@davidfirst davidfirst commented Jun 30, 2025

Replaces vulnerable execSync calls with secure spawnSync to prevent command injection attacks.

@davidfirst davidfirst merged commit e76b00f into master Jun 30, 2025
10 checks passed
@davidfirst davidfirst deleted the fix/mcp-server-command-injection branch June 30, 2025 21:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

3 participants