fig. 01 — GHSA-p4h8-56qp-hpgv, the advisory selected below
// advisories
GHSA-p4h8-56qp-hpgv
HIGH
A crafted hostAlias argument such as -oProxyCommand=... was passed to ssh/scp without an argument terminator. SSH interprets arguments starting with - as options regardless of position, so the option-injection caused SSH to execute the attacker-supplied ProxyCommand locally on the machine running the MCP server — before any network connection. This bypassed the documented protection of # @password