ADB MCP Server is a MCP (Model Context Protocol) server for interacting with Android devices through ADB. In versions 0.1.0 and prior, the MCP Server is written in a way that is vulnerable to command injection vulnerability attacks as part of some of its MCP Server tool definition and implementation. This issue has been patched via commit 041729c.
History

Tue, 14 Oct 2025 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Srmorete
Srmorete adb Mcp Server
CPEs cpe:2.3:a:srmorete:adb_mcp_server:*:*:*:*:*:node.js:*:*
Vendors & Products Srmorete
Srmorete adb Mcp Server

Mon, 29 Sep 2025 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Adb Mcp Project
Adb Mcp Project adb Mcp
Google
Google android
Vendors & Products Adb Mcp Project
Adb Mcp Project adb Mcp
Google
Google android

Thu, 25 Sep 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 25 Sep 2025 13:45:00 +0000

Type Values Removed Values Added
Description ADB MCP Server is a MCP (Model Context Protocol) server for interacting with Android devices through ADB. In versions 0.1.0 and prior, the MCP Server is written in a way that is vulnerable to command injection vulnerability attacks as part of some of its MCP Server tool definition and implementation. This issue has been patched via commit 041729c.
Title Command Injection in adb-mcp MCP Server
Weaknesses CWE-77
CWE-78
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-09-25T13:41:15.676Z

Updated: 2025-09-25T14:36:27.801Z

Reserved: 2025-09-22T14:34:03.471Z

Link: CVE-2025-59834

cve-icon Vulnrichment

Updated: 2025-09-25T14:36:24.461Z

cve-icon NVD

Status : Analyzed

Published: 2025-09-25T14:15:46.357

Modified: 2025-10-14T20:05:46.243

Link: CVE-2025-59834

cve-icon Redhat

No data.