ADB MCP Server is a MCP (Model Context Protocol) server for interacting with Android devices through ADB. In versions 0.1.0 and prior, the MCP Server is written in a way that is vulnerable to command injection vulnerability attacks as part of some of its MCP Server tool definition and implementation. This issue has been patched via commit 041729c.
References
| Link | Resource |
|---|---|
| https://github.com/srmorete/adb-mcp/blob/master/src/index.ts#L334-L355 | Product |
| https://github.com/srmorete/adb-mcp/commit/041729c0b25432df3199ff71b3163a307cf4c28c | Patch |
| https://github.com/srmorete/adb-mcp/security/advisories/GHSA-54j7-grvr-9xwg | Exploit Vendor Advisory |
| https://github.com/srmorete/adb-mcp/security/advisories/GHSA-54j7-grvr-9xwg | Exploit Vendor Advisory |
Configurations
History
14 Oct 2025, 20:05
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Srmorete
Srmorete adb Mcp Server |
|
| CPE | cpe:2.3:a:srmorete:adb_mcp_server:*:*:*:*:*:node.js:*:* | |
| References | () https://github.com/srmorete/adb-mcp/blob/master/src/index.ts#L334-L355 - Product | |
| References | () https://github.com/srmorete/adb-mcp/commit/041729c0b25432df3199ff71b3163a307cf4c28c - Patch | |
| References | () https://github.com/srmorete/adb-mcp/security/advisories/GHSA-54j7-grvr-9xwg - Exploit, Vendor Advisory |
25 Sep 2025, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/srmorete/adb-mcp/security/advisories/GHSA-54j7-grvr-9xwg - |
25 Sep 2025, 14:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-09-25 14:15
Updated : 2025-10-14 20:05
NVD link : CVE-2025-59834
Mitre link : CVE-2025-59834
CVE.ORG link : CVE-2025-59834
JSON object : View
Products Affected
srmorete
- adb_mcp_server
