PT-2026-55216 · Git+2 · Repomix

CVE-2026-49988

·

Published

2026-07-01

·

Updated

2026-07-15

CVSS v4.0

6.9

Medium

VectorAV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Repomix versions prior to 1.14.1
Description The MCP server in Repomix contains a flaw where the flow involving the attach packed output and read repomix output tools allows the registration and reading of arbitrary local .json, .txt, .md, or .xml files. This occurs because these tools bypass the runSecretLint() safety check and the packed-output validation used by the file system read file tool. An attacker or a lower-trust model capable of invoking MCP tools can use attach packed output to register a local file and then call read repomix output to retrieve its full content, effectively bypassing the local file-read secret-scanning boundary. This could lead to the exposure of sensitive plaintext files, such as project configurations or exported tokens.
Recommendations Update to version 1.14.1.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-49988
GHSA-HWPP-H97W-2H3J

Affected Products

Repomix