Serverless Framework versions 4.29.0 through 4.29.2 contain an OS command-injection vulnerability in the built-in experimental MCP server package, @serverless/mcp. The MCP server constructs shell command strings using unvalidated input parameters and passes them to child_process.exec. An attacker can inject shell metacharacters, such as pipes, redirections, or command chaining operators, to cause execution of arbitrary system commands. The core Serverless Framework CLI and deployment functionality are not affected.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
Repository contains a single Python exploit script plus README and MIT license. Primary exploit file: `CTT-Serverless-RCE v1.py` (Python 3). It targets a claimed command-injection flaw in the Serverless Framework MCP server (CVE-2025-69256 / GHSA-rwc2-f344-q6w6), specifically via an unsanitized `workspaceRoots` parameter in the MCP JSON-RPC `list-projects` tool. The script implements a “multi-layer” exploitation strategy (33 layers) that varies timing and payload encoding/wrapping to increase the chance of successful command execution and to evade naive detection. Key capabilities observed from the code and documentation: - Network-based, pre-auth RCE attempt against an MCP server (default port 3000). - Multi-transport intent: imports both `requests` (HTTP) and `websocket` (WebSocket), and README claims HTTP+WebSocket support. - Payload generation engine (`CTT_MCP_Resonance`) that: - Waits for small prime-aligned timing windows (microsecond-scale) before sending attempts. - Produces per-layer entropy markers (`# CTT_L{layer}_E{hash}`) to correlate output. - Applies multiple encodings (raw, base64, URL-encoding, hex escapes) and multiple injection wrappers (shell metacharacters, Node.js `child_process.execSync`, `eval`, and PowerShell). - Orchestration (`main`) accepts a target and command, runs multi-layer exploitation, prints results, and writes a JSON report file `ctt_mcp_results_<target>_<timestamp>.json`. Repository structure/purpose: - `CTT-Serverless-RCE v1.py`: standalone exploit tool intended to execute arbitrary commands on a vulnerable Serverless MCP server by injecting into JSON-RPC parameters. - `README.md`: marketing-style description, claimed affected versions (Serverless Framework 4.29.0–4.29.3), vulnerable file path reference (`packages/mcp/src/tools/list-projects.js`), and example usage including reverse-shell style invocation (example endpoint 192.168.1.100:4444). - `LICENSE`: MIT. Notes on fidelity: The script is clearly designed as an exploit (not merely detection) and includes real payload construction logic and result saving. Some README claims (e.g., CVE, exact affected versions, and “CTT physics” performance metrics) are not verifiable from the provided snippet alone, but the code’s core behavior aligns with a command-injection RCE attempt over a JSON-RPC MCP interface.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.