← Back to CVE List
CVE-2025-59834NVD
Vulnerability Summary
ADB MCP Server is a MCP (Model Context Protocol) server for interacting with Android devices through ADB. In versions 0.1.0 and prior, the MCP Server is written in a way that is vulnerable to command injection vulnerability attacks as part of some of its MCP Server tool definition and implementation. This issue has been patched via commit 041729c.
CVSS v3.1 Base Metrics — Score 9.8 (CRITICAL)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh
Affected & Patched Versions
- Srmorete Adb Mcp Server <= 0.1.0
Not provided by NVD for this CVE.
External References
- https://github.com/srmorete/adb-mcp/blob/master/src/index.ts#L334-L355
- https://github.com/srmorete/adb-mcp/commit/041729c0b25432df3199ff71b3163a307cf4c28c
- https://github.com/srmorete/adb-mcp/security/advisories/GHSA-54j7-grvr-9xwg
- https://github.com/srmorete/adb-mcp/security/advisories/GHSA-54j7-grvr-9xwg