npm›@akoskm/create-mcp-server-stdio›CVE-2025-549949.8 CRITICAL@akoskm/create-mcp-server-stdio is vulnerable to MCP Server Command Injection through `exec` APIUser initiated and remote command injection on a running MCP Server.