Command injection
When input from outside, such as a tool argument, ends up being run as part of a shell command.
The usual cause is building a command as a string and handing it to a shell, with an argument pasted in. A shell reads characters such as a semicolon or a pipe as instructions, so an argument that contains them runs commands of its own.
The fix is well known: pass the program and its arguments separately, so no shell ever parses the input. In an MCP server the input is written by a model, which can itself be steered by text it has read, so an injection can be triggered without anybody typing anything malicious.
It turns a tool into a way to run anything on the machine the server runs on, with the server's privileges. It is what the command execution row of the rubric looks for.
Trusting arguments because a model wrote them. A model passes on whatever it was led to, including text from a web page or a document it was asked to read.
Related terms
See Command injection on a real listing
Every term here shows up in the catalogue next to a real result, with the findings published and the limits stated. Free to browse, no account needed.
Open the catalogue