CVE-2026-6942: R2mcp Incomplete Shell Metachar Filter Cve 2026 6942
Incomplete shell metacharacter denylist used to sanitize an r2/shell command string. The filter either (a) looks for the literal "$ (" (with a stray space) instead of "$(", so command-substitution payloads slip past, or (b) only neutralizes the first byte when it equals '!', allowing bypass via ';', '&', or newline followed by '!cmd' (e.g. "?V;!id"). Filtere
greprules fetch cve-2026-6942-r2mcp-incomplete-shell-metachar-filter-cve-2026-6942 --engine opengrepDescription
Incomplete shell metacharacter denylist used to sanitize an r2/shell command string. The filter either (a) looks for the literal "$ (" (with a stray space) instead of "$(", so command-substitution payloads slip past, or (b) only neutralizes the first byte when it equals '!', allowing bypass via ';', '&', or newline followed by '!cmd' (e.g. "?V;!id"). Filtere
Community feedback
0 rule-level signals from signed-in users.
- Useful reports
- 0
- Context false positives
- 0
- Metadata suggestions
- 0
Contextual precision
Aggregated from approved scan feedback. False-positive reports describe observed scan contexts, not a global rule verdict.
- Findings observed
- 0
- Projects
- 0
- Reporters
- 0
Precision details are collecting more signed-in reports before verdict counts or ratios are emphasized.
No approved finding verdicts yet.
No scan diagnostics reported yet.