PT-2026-85550 · Cyanheads · Git-Mcp-Server
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
git-mcp-server 2.15.1 contains an argument injection vulnerability in the ref and object parameters of git log, git diff, and git show tools that lack leading-dash validation. Attackers can inject git command-line options like --output= to write files outside the repository to arbitrary paths accessible by the process.
Exploit
Fix
Argument Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Git-Mcp-Server