GHSA-3q26-f695-pp76
HIGHCVE-2025-53107A command injection vulnerability exists in the git-mcp-server MCP Server. The vulnerability is caused by the unsanitized use of input parameters within a call to childprocess.exec, enabling an attacker to inject arbitrary system commands. Successful exploitation can lead to remote code execution under the server process's privileges.
- Affected
- <= 2.1.4
- Fixed in
- 2.1.5
- Weakness
- CWE-77
- Published
- 2025-06-30
- Source
- github