PT-2026-55216 · Git+2 · Repomix
CVE-2026-49988
·
Published
2026-07-01
·
Updated
2026-07-15
CVSS v4.0
6.9
Medium
| Vector | AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Repomix versions prior to 1.14.1
Description
The MCP server in Repomix contains a flaw where the flow involving the
attach packed output and read repomix output tools allows the registration and reading of arbitrary local .json, .txt, .md, or .xml files. This occurs because these tools bypass the runSecretLint() safety check and the packed-output validation used by the file system read file tool. An attacker or a lower-trust model capable of invoking MCP tools can use attach packed output to register a local file and then call read repomix output to retrieve its full content, effectively bypassing the local file-read secret-scanning boundary. This could lead to the exposure of sensitive plaintext files, such as project configurations or exported tokens.Recommendations
Update to version 1.14.1.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Repomix