Modelcontextprotocol / Servers
6 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-27735 | mcp-server-git : Path traversal in git_add allows staging files outside repository boundaries | MEDIUM | 6.4 | Feb 25, 2026 |
| CVE-2025-68145 | mcp-server-git has missing path validation when using --repository flag | MEDIUM | 6.4 | Dec 17, 2025 |
| CVE-2025-68144 | mcp-server-git argument injection in git_diff and git_checkout functions allows overwriting local files | MEDIUM | 6.3 | Dec 17, 2025 |
| CVE-2025-68143 | mcp-server-git's unrestricted git_init tool allows repository creation at arbitrary filesystem locations | MEDIUM | 6.5 | Dec 17, 2025 |
| CVE-2025-53109 | Model Context Protocol Servers Vulnerable to Path Validation Bypass via Prefix Matching and Symlink Handling | HIGH | 7.3 | Jul 2, 2025 |
| CVE-2025-53110 | Model Context Protocol Servers Vulnerable to Path Validation Bypass via Colliding Path Prefix | HIGH | 7.3 | Jul 2, 2025 |
Showing 1 to 6 of 6 CVEs