CVE-2025-59834
Last modified
CVE-2025-59834 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. ADB MCP Server is a MCP (Model Context Protocol) server for interacting with Android devices through ADB. In versions 0.1.0 and prior, the MCP Server is written in a way that is vulnerable to command injection vulnerability attacks as part of some of its MCP Server tool definition and implementation. EPSS estimates a 2.29% chance of exploitation in the next 30 days.
Description
ADB MCP Server is a MCP (Model Context Protocol) server for interacting with Android devices through ADB. In versions 0.1.0 and prior, the MCP Server is written in a way that is vulnerable to command injection vulnerability attacks as part of some of its MCP Server tool definition and implementation. This issue has been patched via commit 041729c.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Srmorete | Adb Mcp Server | <= 0.1.0 |
References
- https://github.com/srmorete/adb-mcp/security/advisories/GHSA-54j7-grvr-9xwgExploit, Vendor Advisory
- https://github.com/srmorete/adb-mcp/security/advisories/GHSA-54j7-grvr-9xwgExploit, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-59834?
How severe is CVE-2025-59834?
How do I fix CVE-2025-59834?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-59829Claude Code is an agentic coding tool. Versions below 1.0.12…6.5
- CVE-2025-5983The Meta Tag Manager WordPress plugin before 3.3 does not re…6.5
- CVE-2025-59830Rack is a modular Ruby web server interface. Prior to versio…7.5
- CVE-2025-59831git-commiters is a Node.js function module providing committ…8.8
- CVE-2025-59832Horilla is a free and open source Human Resource Management …9.9
- CVE-2025-59833Flag Forge is a Capture The Flag (CTF) platform. In versions…7.5
- CVE-2025-59835LangBot is a global IM bot platform designed for LLMs. In ve…8.6
- CVE-2025-59836Omni manages Kubernetes on bare metal, virtual machines, or …7.5
- CVE-2025-59837Astro is a web framework that includes an image proxy. In ve…7.2
- CVE-2025-59838Monkeytype is a minimalistic and customizable typing test. I…5.4
- CVE-2025-59839The EmbedVideo Extension is a MediaWiki extension which adds…5.4
- CVE-2025-5984A vulnerability has been found in SourceCodester Online Stud…5.4
Are you affected by CVE-2025-59834?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
