npm›@akoskm/create-mcp-server-stdio›CVE-2025-54994@akoskm/create-mcp-server-stdio is vulnerable to MCP Server Command Injection through `exec` APIUser initiated and remote command injection on a running MCP Server.