CVE-2025-69256 describes a command injection vulnerability in the Serverless Framework's experimental MCP server feature, affecting versions 4.29.0 through 4.29.2. This flaw, caused by unsanitized input in child_process.exec calls, allows remote code execution by injecting arbitrary system commands. Rated 7.5 HIGH on CVSS, exploitation requires user interaction and can lead to high impact on confidentiality, integrity, and availability. While the FAUCET Risk Score is 85/100, the vulnerability affects less than 0.1% of users, and there is currently no public exploit code, active exploitation, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.29.0, < 4.29.3CPE matchmatch criteria | cpe:2.3:a:serverless:serverless:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.