modelcontextprotocol / modelcontextprotocol/python-sdk
Don’t use shell=True in mcp dev subprocess on Windows (command injection risk)
Ninguém assumiu esta issue ainda.
- Linguagem predominante
- Python
- Estrelas
- 24.3k
- Forks
- 4k
- Merge médio
- 1d 1h
- PRs com merge (30d)
- 31
Descrição
Initial Checks
- I confirm that I'm using the latest version of MCP Python SDK
- I confirm that I searched for my issue in https://github.com/modelcontextprotocol/python-sdk/issues before opening this issue
Description
What’s happening:
When you run the mcp dev command on Windows, it starts another program using a method (subprocess.run with shell=True) that lets the Windows command prompt (cmd.exe) handle the command. This is risky because if any part of the command includes special characters (like &, |, %, etc.), Windows might run something you didn’t expect — even another program, if the file path or arguments are weirdly named or crafted.
Why this is a real problem:
- This isn’t just a theory — it’s a well-known risk with
shell=Truein Python. If anyone (or any script) can control part of the file path or arguments, they might be able to run extra commands on your computer. - The Python documentation says to avoid
shell=Truewhen possible for exactly this reason. - The fix is easy: use
shell=Falseand make sure the right Windows executable is picked (likenpx.cmd). - This keeps things safe and works the same on all systems.
What should happen instead:
- The command should be run without
shell=Trueon Windows, just like it is on Linux/Mac. - File paths and arguments should always be passed as a list, not a single string.
How this could be abused:
- If someone manages to sneak a file or argument with a shell special character into your project, running
mcp devcould run extra commands (for example, opening Calculator if the file had&calcin its name).
Please fix:
- Remove
shell=Truefrom thesubprocess.runcall insrc/mcp/cli/cli.py(Windows part). - Make sure the command and its arguments are always passed as a list.
- Make sure it works on Windows by using the right executable (like
npx.cmd).
Thanks!
Example Code
# Example of risky situation on Windows:
# If a file is named "server&calc.py" and you run:
# mcp dev path\to\server&calc.py
# Windows might run Calculator because of the &
# Please see src/mcp/cli/cli.py (mcp dev command) for the subprocess.run([npx_cmd, ...], shell=True, ...)
Python & MCP Python SDK
Python 3.11, Windows 11, latest MCP Python SDK (main branch, August 2025)
Guia de contribuição
Primeiros passos
- Leia a issue inteira e depois o guia de contribuição do projeto.
- Comente na issue dizendo que vai assumir — evita que duas pessoas façam o mesmo trabalho.
- Faça um fork do repositório e trabalhe em uma branch.
- Abra um pull request que referencie o número da issue.
Direção de pesquisa
Comece em src/mcp/cli/cli.py, na chamada de subprocess.run de mcp dev para Windows. Verifique como o comando e os argumentos são montados e, em seguida, confirme que o executável é selecionado adequadamente para Windows e que os argumentos são passados como uma lista sem shell=True. Está concluído quando mcp dev é executado no Windows e os metacaracteres do shell em caminhos ou argumentos não são interpretados como comandos extras.
Escrita pelo modelo de indexação a partir do texto da issue.
Avaliação
- Stack de tecnologia
- python
- Domínio
- cli, security
- Tipo de issue
- Bug
- Dificuldade
- 2/5
- Tempo estimado
- 1-3 horas
- Status de atividade
- Pouca atividade
- Clareza
- Claramente especificada
- Facilidade para iniciantes
- 72/100