mcp-server-git
Model Context Protocol Servers
Activity
- Latest release
- 3w ago
- Total releases
- 19
- Cadence
- ~17 days
- Last 12 months
- 7
Reach
- Stars
- 90.1k
Details
- License
- MIT
- First release
- Nov 21, 2024
| Version | Released | |
|---|---|---|
2026.8.18
minor
| ||
2026.7.10
minor
| ||
2026.6.16
patch
| ||
2026.6.4
minor
| ||
2026.1.14
major
| ||
2025.12.18
minor
1 CVE
CVE-2026-27735
PYSEC-2026-2630
GHSA-vjqx-cfc4-9h6v
Jul 13, 2026
mcp-server-git : Path traversal in git_add allows staging files outside repository boundaries
Low
Network
Low
None
In mcp-server-git thanks https://hackerone.com/0dd-g for reporting and contributing the fix. Affected versions
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
2025.1.14
2025.11.25
2025.12.18
+ 2 more Show less
2025.7.1
2025.9.25
Fixed in
2026.1.14
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2025.11.25
minor
3 CVEs
CVE-2026-27735
PYSEC-2026-2630
GHSA-vjqx-cfc4-9h6v
Jul 13, 2026
mcp-server-git : Path traversal in git_add allows staging files outside repository boundaries
Low
Network
Low
None
In mcp-server-git thanks https://hackerone.com/0dd-g for reporting and contributing the fix. Affected versions
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
2025.1.14
2025.11.25
2025.12.18
+ 2 more Show less
2025.7.1
2025.9.25
Fixed in
2026.1.14
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-68145
PYSEC-2026-1623
GHSA-j22h-9j4x-23w5
Jul 07, 2026
mcp-server-git has missing path validation when using --repository flag
Low
Network
Low
None
In mcp-server-git versions prior to 2025.12.18, when the server is started with the --repository flag to restrict operations to a specific repository path, it did not validate that repo_path arguments in subsequent tool calls were actually within that configured path. This could allow tool calls to operate on other repositories accessible to the server process. The fix adds path validation that resolves both the configured repository and the requested path (following symlinks) and verifies the requested path is within the allowed repository before executing any git operations. Users are advised to upgrade to 2025.12.18 to remediate this issue. Thank you to https://hackerone.com/yardenporat for reporting. Affected versions
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
2025.1.14
2025.11.25
2025.7.1
+ 1 more Show less
2025.9.25
Fixed in
2025.12.18
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68144
PYSEC-2026-1622
GHSA-9xwc-hfwc-8w59
Jul 07, 2026
mcp-server-git argument injection in git_diff and git_checkout functions allows overwriting local files
Low
Network
Low
None
In mcp-server-git versions prior to 2025.12.18, the git_diff and git_checkout functions passed user-controlled arguments directly to git CLI commands without sanitization. Flag-like values (e.g., Thank you to https://hackerone.com/yardenporat for reporting. Affected versions
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
2025.1.14
2025.11.25
2025.7.1
+ 1 more Show less
2025.9.25
Fixed in
2025.12.18
References Updated Jul 07, 2026 · Source: OSV.dev | ||
2025.9.25
minor
3 CVEs
CVE-2026-27735
PYSEC-2026-2630
GHSA-vjqx-cfc4-9h6v
Jul 13, 2026
mcp-server-git : Path traversal in git_add allows staging files outside repository boundaries
Low
Network
Low
None
In mcp-server-git thanks https://hackerone.com/0dd-g for reporting and contributing the fix. Affected versions
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
2025.1.14
2025.11.25
2025.12.18
+ 2 more Show less
2025.7.1
2025.9.25
Fixed in
2026.1.14
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-68145
PYSEC-2026-1623
GHSA-j22h-9j4x-23w5
Jul 07, 2026
mcp-server-git has missing path validation when using --repository flag
Low
Network
Low
None
In mcp-server-git versions prior to 2025.12.18, when the server is started with the --repository flag to restrict operations to a specific repository path, it did not validate that repo_path arguments in subsequent tool calls were actually within that configured path. This could allow tool calls to operate on other repositories accessible to the server process. The fix adds path validation that resolves both the configured repository and the requested path (following symlinks) and verifies the requested path is within the allowed repository before executing any git operations. Users are advised to upgrade to 2025.12.18 to remediate this issue. Thank you to https://hackerone.com/yardenporat for reporting. Affected versions
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
2025.1.14
2025.11.25
2025.7.1
+ 1 more Show less
2025.9.25
Fixed in
2025.12.18
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68144
PYSEC-2026-1622
GHSA-9xwc-hfwc-8w59
Jul 07, 2026
mcp-server-git argument injection in git_diff and git_checkout functions allows overwriting local files
Low
Network
Low
None
In mcp-server-git versions prior to 2025.12.18, the git_diff and git_checkout functions passed user-controlled arguments directly to git CLI commands without sanitization. Flag-like values (e.g., Thank you to https://hackerone.com/yardenporat for reporting. Affected versions
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
2025.1.14
2025.11.25
2025.7.1
+ 1 more Show less
2025.9.25
Fixed in
2025.12.18
References Updated Jul 07, 2026 · Source: OSV.dev | ||
2025.7.1
minor
4 CVEs
CVE-2026-27735
PYSEC-2026-2630
GHSA-vjqx-cfc4-9h6v
Jul 13, 2026
mcp-server-git : Path traversal in git_add allows staging files outside repository boundaries
Low
Network
Low
None
In mcp-server-git thanks https://hackerone.com/0dd-g for reporting and contributing the fix. Affected versions
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
2025.1.14
2025.11.25
2025.12.18
+ 2 more Show less
2025.7.1
2025.9.25
Fixed in
2026.1.14
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-68145
PYSEC-2026-1623
GHSA-j22h-9j4x-23w5
Jul 07, 2026
mcp-server-git has missing path validation when using --repository flag
Low
Network
Low
None
In mcp-server-git versions prior to 2025.12.18, when the server is started with the --repository flag to restrict operations to a specific repository path, it did not validate that repo_path arguments in subsequent tool calls were actually within that configured path. This could allow tool calls to operate on other repositories accessible to the server process. The fix adds path validation that resolves both the configured repository and the requested path (following symlinks) and verifies the requested path is within the allowed repository before executing any git operations. Users are advised to upgrade to 2025.12.18 to remediate this issue. Thank you to https://hackerone.com/yardenporat for reporting. Affected versions
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
2025.1.14
2025.11.25
2025.7.1
+ 1 more Show less
2025.9.25
Fixed in
2025.12.18
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68144
PYSEC-2026-1622
GHSA-9xwc-hfwc-8w59
Jul 07, 2026
mcp-server-git argument injection in git_diff and git_checkout functions allows overwriting local files
Low
Network
Low
None
In mcp-server-git versions prior to 2025.12.18, the git_diff and git_checkout functions passed user-controlled arguments directly to git CLI commands without sanitization. Flag-like values (e.g., Thank you to https://hackerone.com/yardenporat for reporting. Affected versions
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
2025.1.14
2025.11.25
2025.7.1
+ 1 more Show less
2025.9.25
Fixed in
2025.12.18
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68143
PYSEC-2026-1621
GHSA-5cgr-j3jf-jw3v
Jul 07, 2026
mcp-server-git's unrestricted git_init tool allows repository creation at arbitrary filesystem locations
Low
Network
Low
None
In mcp-server-git versions prior to 2025.9.25, the git_init tool accepted arbitrary filesystem paths and created Git repositories without validating the target location. Unlike other tools which required an existing repository, git_init could operate on any directory accessible to the server process, making those directories eligible for subsequent git operations. The tool was removed entirely, as the server is intended to operate on existing repositories only. Users are advised to upgrade to 2025.9.25 or newer to remediate this issue. Thank you to https://hackerone.com/yardenporat for disclosure, @0dd for contributing the fix. Affected versions
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
2025.1.14
2025.7.1
Fixed in
2025.9.25
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
2025.1.14
major
4 CVEs
CVE-2026-27735
PYSEC-2026-2630
GHSA-vjqx-cfc4-9h6v
Jul 13, 2026
mcp-server-git : Path traversal in git_add allows staging files outside repository boundaries
Low
Network
Low
None
In mcp-server-git thanks https://hackerone.com/0dd-g for reporting and contributing the fix. Affected versions
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
2025.1.14
2025.11.25
2025.12.18
+ 2 more Show less
2025.7.1
2025.9.25
Fixed in
2026.1.14
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-68145
PYSEC-2026-1623
GHSA-j22h-9j4x-23w5
Jul 07, 2026
mcp-server-git has missing path validation when using --repository flag
Low
Network
Low
None
In mcp-server-git versions prior to 2025.12.18, when the server is started with the --repository flag to restrict operations to a specific repository path, it did not validate that repo_path arguments in subsequent tool calls were actually within that configured path. This could allow tool calls to operate on other repositories accessible to the server process. The fix adds path validation that resolves both the configured repository and the requested path (following symlinks) and verifies the requested path is within the allowed repository before executing any git operations. Users are advised to upgrade to 2025.12.18 to remediate this issue. Thank you to https://hackerone.com/yardenporat for reporting. Affected versions
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
2025.1.14
2025.11.25
2025.7.1
+ 1 more Show less
2025.9.25
Fixed in
2025.12.18
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68144
PYSEC-2026-1622
GHSA-9xwc-hfwc-8w59
Jul 07, 2026
mcp-server-git argument injection in git_diff and git_checkout functions allows overwriting local files
Low
Network
Low
None
In mcp-server-git versions prior to 2025.12.18, the git_diff and git_checkout functions passed user-controlled arguments directly to git CLI commands without sanitization. Flag-like values (e.g., Thank you to https://hackerone.com/yardenporat for reporting. Affected versions
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
2025.1.14
2025.11.25
2025.7.1
+ 1 more Show less
2025.9.25
Fixed in
2025.12.18
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68143
PYSEC-2026-1621
GHSA-5cgr-j3jf-jw3v
Jul 07, 2026
mcp-server-git's unrestricted git_init tool allows repository creation at arbitrary filesystem locations
Low
Network
Low
None
In mcp-server-git versions prior to 2025.9.25, the git_init tool accepted arbitrary filesystem paths and created Git repositories without validating the target location. Unlike other tools which required an existing repository, git_init could operate on any directory accessible to the server process, making those directories eligible for subsequent git operations. The tool was removed entirely, as the server is intended to operate on existing repositories only. Users are advised to upgrade to 2025.9.25 or newer to remediate this issue. Thank you to https://hackerone.com/yardenporat for disclosure, @0dd for contributing the fix. Affected versions
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
2025.1.14
2025.7.1
Fixed in
2025.9.25
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.6.2
patch
4 CVEs
CVE-2026-27735
PYSEC-2026-2630
GHSA-vjqx-cfc4-9h6v
Jul 13, 2026
mcp-server-git : Path traversal in git_add allows staging files outside repository boundaries
Low
Network
Low
None
In mcp-server-git thanks https://hackerone.com/0dd-g for reporting and contributing the fix. Affected versions
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
2025.1.14
2025.11.25
2025.12.18
+ 2 more Show less
2025.7.1
2025.9.25
Fixed in
2026.1.14
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-68145
PYSEC-2026-1623
GHSA-j22h-9j4x-23w5
Jul 07, 2026
mcp-server-git has missing path validation when using --repository flag
Low
Network
Low
None
In mcp-server-git versions prior to 2025.12.18, when the server is started with the --repository flag to restrict operations to a specific repository path, it did not validate that repo_path arguments in subsequent tool calls were actually within that configured path. This could allow tool calls to operate on other repositories accessible to the server process. The fix adds path validation that resolves both the configured repository and the requested path (following symlinks) and verifies the requested path is within the allowed repository before executing any git operations. Users are advised to upgrade to 2025.12.18 to remediate this issue. Thank you to https://hackerone.com/yardenporat for reporting. Affected versions
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
2025.1.14
2025.11.25
2025.7.1
+ 1 more Show less
2025.9.25
Fixed in
2025.12.18
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68144
PYSEC-2026-1622
GHSA-9xwc-hfwc-8w59
Jul 07, 2026
mcp-server-git argument injection in git_diff and git_checkout functions allows overwriting local files
Low
Network
Low
None
In mcp-server-git versions prior to 2025.12.18, the git_diff and git_checkout functions passed user-controlled arguments directly to git CLI commands without sanitization. Flag-like values (e.g., Thank you to https://hackerone.com/yardenporat for reporting. Affected versions
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
2025.1.14
2025.11.25
2025.7.1
+ 1 more Show less
2025.9.25
Fixed in
2025.12.18
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68143
PYSEC-2026-1621
GHSA-5cgr-j3jf-jw3v
Jul 07, 2026
mcp-server-git's unrestricted git_init tool allows repository creation at arbitrary filesystem locations
Low
Network
Low
None
In mcp-server-git versions prior to 2025.9.25, the git_init tool accepted arbitrary filesystem paths and created Git repositories without validating the target location. Unlike other tools which required an existing repository, git_init could operate on any directory accessible to the server process, making those directories eligible for subsequent git operations. The tool was removed entirely, as the server is intended to operate on existing repositories only. Users are advised to upgrade to 2025.9.25 or newer to remediate this issue. Thank you to https://hackerone.com/yardenporat for disclosure, @0dd for contributing the fix. Affected versions
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
2025.1.14
2025.7.1
Fixed in
2025.9.25
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.6.1
patch
4 CVEs
CVE-2026-27735
PYSEC-2026-2630
GHSA-vjqx-cfc4-9h6v
Jul 13, 2026
mcp-server-git : Path traversal in git_add allows staging files outside repository boundaries
Low
Network
Low
None
In mcp-server-git thanks https://hackerone.com/0dd-g for reporting and contributing the fix. Affected versions
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
2025.1.14
2025.11.25
2025.12.18
+ 2 more Show less
2025.7.1
2025.9.25
Fixed in
2026.1.14
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-68145
PYSEC-2026-1623
GHSA-j22h-9j4x-23w5
Jul 07, 2026
mcp-server-git has missing path validation when using --repository flag
Low
Network
Low
None
In mcp-server-git versions prior to 2025.12.18, when the server is started with the --repository flag to restrict operations to a specific repository path, it did not validate that repo_path arguments in subsequent tool calls were actually within that configured path. This could allow tool calls to operate on other repositories accessible to the server process. The fix adds path validation that resolves both the configured repository and the requested path (following symlinks) and verifies the requested path is within the allowed repository before executing any git operations. Users are advised to upgrade to 2025.12.18 to remediate this issue. Thank you to https://hackerone.com/yardenporat for reporting. Affected versions
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
2025.1.14
2025.11.25
2025.7.1
+ 1 more Show less
2025.9.25
Fixed in
2025.12.18
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68144
PYSEC-2026-1622
GHSA-9xwc-hfwc-8w59
Jul 07, 2026
mcp-server-git argument injection in git_diff and git_checkout functions allows overwriting local files
Low
Network
Low
None
In mcp-server-git versions prior to 2025.12.18, the git_diff and git_checkout functions passed user-controlled arguments directly to git CLI commands without sanitization. Flag-like values (e.g., Thank you to https://hackerone.com/yardenporat for reporting. Affected versions
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
2025.1.14
2025.11.25
2025.7.1
+ 1 more Show less
2025.9.25
Fixed in
2025.12.18
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68143
PYSEC-2026-1621
GHSA-5cgr-j3jf-jw3v
Jul 07, 2026
mcp-server-git's unrestricted git_init tool allows repository creation at arbitrary filesystem locations
Low
Network
Low
None
In mcp-server-git versions prior to 2025.9.25, the git_init tool accepted arbitrary filesystem paths and created Git repositories without validating the target location. Unlike other tools which required an existing repository, git_init could operate on any directory accessible to the server process, making those directories eligible for subsequent git operations. The tool was removed entirely, as the server is intended to operate on existing repositories only. Users are advised to upgrade to 2025.9.25 or newer to remediate this issue. Thank you to https://hackerone.com/yardenporat for disclosure, @0dd for contributing the fix. Affected versions
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
2025.1.14
2025.7.1
Fixed in
2025.9.25
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.6.0
minor
4 CVEs
CVE-2026-27735
PYSEC-2026-2630
GHSA-vjqx-cfc4-9h6v
Jul 13, 2026
mcp-server-git : Path traversal in git_add allows staging files outside repository boundaries
Low
Network
Low
None
In mcp-server-git thanks https://hackerone.com/0dd-g for reporting and contributing the fix. Affected versions
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
2025.1.14
2025.11.25
2025.12.18
+ 2 more Show less
2025.7.1
2025.9.25
Fixed in
2026.1.14
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-68145
PYSEC-2026-1623
GHSA-j22h-9j4x-23w5
Jul 07, 2026
mcp-server-git has missing path validation when using --repository flag
Low
Network
Low
None
In mcp-server-git versions prior to 2025.12.18, when the server is started with the --repository flag to restrict operations to a specific repository path, it did not validate that repo_path arguments in subsequent tool calls were actually within that configured path. This could allow tool calls to operate on other repositories accessible to the server process. The fix adds path validation that resolves both the configured repository and the requested path (following symlinks) and verifies the requested path is within the allowed repository before executing any git operations. Users are advised to upgrade to 2025.12.18 to remediate this issue. Thank you to https://hackerone.com/yardenporat for reporting. Affected versions
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
2025.1.14
2025.11.25
2025.7.1
+ 1 more Show less
2025.9.25
Fixed in
2025.12.18
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68144
PYSEC-2026-1622
GHSA-9xwc-hfwc-8w59
Jul 07, 2026
mcp-server-git argument injection in git_diff and git_checkout functions allows overwriting local files
Low
Network
Low
None
In mcp-server-git versions prior to 2025.12.18, the git_diff and git_checkout functions passed user-controlled arguments directly to git CLI commands without sanitization. Flag-like values (e.g., Thank you to https://hackerone.com/yardenporat for reporting. Affected versions
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
2025.1.14
2025.11.25
2025.7.1
+ 1 more Show less
2025.9.25
Fixed in
2025.12.18
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68143
PYSEC-2026-1621
GHSA-5cgr-j3jf-jw3v
Jul 07, 2026
mcp-server-git's unrestricted git_init tool allows repository creation at arbitrary filesystem locations
Low
Network
Low
None
In mcp-server-git versions prior to 2025.9.25, the git_init tool accepted arbitrary filesystem paths and created Git repositories without validating the target location. Unlike other tools which required an existing repository, git_init could operate on any directory accessible to the server process, making those directories eligible for subsequent git operations. The tool was removed entirely, as the server is intended to operate on existing repositories only. Users are advised to upgrade to 2025.9.25 or newer to remediate this issue. Thank you to https://hackerone.com/yardenporat for disclosure, @0dd for contributing the fix. Affected versions
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
2025.1.14
2025.7.1
Fixed in
2025.9.25
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.5.1
patch
4 CVEs
CVE-2026-27735
PYSEC-2026-2630
GHSA-vjqx-cfc4-9h6v
Jul 13, 2026
mcp-server-git : Path traversal in git_add allows staging files outside repository boundaries
Low
Network
Low
None
In mcp-server-git thanks https://hackerone.com/0dd-g for reporting and contributing the fix. Affected versions
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
2025.1.14
2025.11.25
2025.12.18
+ 2 more Show less
2025.7.1
2025.9.25
Fixed in
2026.1.14
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-68145
PYSEC-2026-1623
GHSA-j22h-9j4x-23w5
Jul 07, 2026
mcp-server-git has missing path validation when using --repository flag
Low
Network
Low
None
In mcp-server-git versions prior to 2025.12.18, when the server is started with the --repository flag to restrict operations to a specific repository path, it did not validate that repo_path arguments in subsequent tool calls were actually within that configured path. This could allow tool calls to operate on other repositories accessible to the server process. The fix adds path validation that resolves both the configured repository and the requested path (following symlinks) and verifies the requested path is within the allowed repository before executing any git operations. Users are advised to upgrade to 2025.12.18 to remediate this issue. Thank you to https://hackerone.com/yardenporat for reporting. Affected versions
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
2025.1.14
2025.11.25
2025.7.1
+ 1 more Show less
2025.9.25
Fixed in
2025.12.18
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68144
PYSEC-2026-1622
GHSA-9xwc-hfwc-8w59
Jul 07, 2026
mcp-server-git argument injection in git_diff and git_checkout functions allows overwriting local files
Low
Network
Low
None
In mcp-server-git versions prior to 2025.12.18, the git_diff and git_checkout functions passed user-controlled arguments directly to git CLI commands without sanitization. Flag-like values (e.g., Thank you to https://hackerone.com/yardenporat for reporting. Affected versions
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
2025.1.14
2025.11.25
2025.7.1
+ 1 more Show less
2025.9.25
Fixed in
2025.12.18
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68143
PYSEC-2026-1621
GHSA-5cgr-j3jf-jw3v
Jul 07, 2026
mcp-server-git's unrestricted git_init tool allows repository creation at arbitrary filesystem locations
Low
Network
Low
None
In mcp-server-git versions prior to 2025.9.25, the git_init tool accepted arbitrary filesystem paths and created Git repositories without validating the target location. Unlike other tools which required an existing repository, git_init could operate on any directory accessible to the server process, making those directories eligible for subsequent git operations. The tool was removed entirely, as the server is intended to operate on existing repositories only. Users are advised to upgrade to 2025.9.25 or newer to remediate this issue. Thank you to https://hackerone.com/yardenporat for disclosure, @0dd for contributing the fix. Affected versions
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
2025.1.14
2025.7.1
Fixed in
2025.9.25
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.5.0
minor
4 CVEs
CVE-2026-27735
PYSEC-2026-2630
GHSA-vjqx-cfc4-9h6v
Jul 13, 2026
mcp-server-git : Path traversal in git_add allows staging files outside repository boundaries
Low
Network
Low
None
In mcp-server-git thanks https://hackerone.com/0dd-g for reporting and contributing the fix. Affected versions
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
2025.1.14
2025.11.25
2025.12.18
+ 2 more Show less
2025.7.1
2025.9.25
Fixed in
2026.1.14
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-68145
PYSEC-2026-1623
GHSA-j22h-9j4x-23w5
Jul 07, 2026
mcp-server-git has missing path validation when using --repository flag
Low
Network
Low
None
In mcp-server-git versions prior to 2025.12.18, when the server is started with the --repository flag to restrict operations to a specific repository path, it did not validate that repo_path arguments in subsequent tool calls were actually within that configured path. This could allow tool calls to operate on other repositories accessible to the server process. The fix adds path validation that resolves both the configured repository and the requested path (following symlinks) and verifies the requested path is within the allowed repository before executing any git operations. Users are advised to upgrade to 2025.12.18 to remediate this issue. Thank you to https://hackerone.com/yardenporat for reporting. Affected versions
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
2025.1.14
2025.11.25
2025.7.1
+ 1 more Show less
2025.9.25
Fixed in
2025.12.18
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68144
PYSEC-2026-1622
GHSA-9xwc-hfwc-8w59
Jul 07, 2026
mcp-server-git argument injection in git_diff and git_checkout functions allows overwriting local files
Low
Network
Low
None
In mcp-server-git versions prior to 2025.12.18, the git_diff and git_checkout functions passed user-controlled arguments directly to git CLI commands without sanitization. Flag-like values (e.g., Thank you to https://hackerone.com/yardenporat for reporting. Affected versions
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
2025.1.14
2025.11.25
2025.7.1
+ 1 more Show less
2025.9.25
Fixed in
2025.12.18
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68143
PYSEC-2026-1621
GHSA-5cgr-j3jf-jw3v
Jul 07, 2026
mcp-server-git's unrestricted git_init tool allows repository creation at arbitrary filesystem locations
Low
Network
Low
None
In mcp-server-git versions prior to 2025.9.25, the git_init tool accepted arbitrary filesystem paths and created Git repositories without validating the target location. Unlike other tools which required an existing repository, git_init could operate on any directory accessible to the server process, making those directories eligible for subsequent git operations. The tool was removed entirely, as the server is intended to operate on existing repositories only. Users are advised to upgrade to 2025.9.25 or newer to remediate this issue. Thank you to https://hackerone.com/yardenporat for disclosure, @0dd for contributing the fix. Affected versions
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
2025.1.14
2025.7.1
Fixed in
2025.9.25
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.4.1
patch
4 CVEs
CVE-2026-27735
PYSEC-2026-2630
GHSA-vjqx-cfc4-9h6v
Jul 13, 2026
mcp-server-git : Path traversal in git_add allows staging files outside repository boundaries
Low
Network
Low
None
In mcp-server-git thanks https://hackerone.com/0dd-g for reporting and contributing the fix. Affected versions
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
2025.1.14
2025.11.25
2025.12.18
+ 2 more Show less
2025.7.1
2025.9.25
Fixed in
2026.1.14
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-68145
PYSEC-2026-1623
GHSA-j22h-9j4x-23w5
Jul 07, 2026
mcp-server-git has missing path validation when using --repository flag
Low
Network
Low
None
In mcp-server-git versions prior to 2025.12.18, when the server is started with the --repository flag to restrict operations to a specific repository path, it did not validate that repo_path arguments in subsequent tool calls were actually within that configured path. This could allow tool calls to operate on other repositories accessible to the server process. The fix adds path validation that resolves both the configured repository and the requested path (following symlinks) and verifies the requested path is within the allowed repository before executing any git operations. Users are advised to upgrade to 2025.12.18 to remediate this issue. Thank you to https://hackerone.com/yardenporat for reporting. Affected versions
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
2025.1.14
2025.11.25
2025.7.1
+ 1 more Show less
2025.9.25
Fixed in
2025.12.18
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68144
PYSEC-2026-1622
GHSA-9xwc-hfwc-8w59
Jul 07, 2026
mcp-server-git argument injection in git_diff and git_checkout functions allows overwriting local files
Low
Network
Low
None
In mcp-server-git versions prior to 2025.12.18, the git_diff and git_checkout functions passed user-controlled arguments directly to git CLI commands without sanitization. Flag-like values (e.g., Thank you to https://hackerone.com/yardenporat for reporting. Affected versions
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
2025.1.14
2025.11.25
2025.7.1
+ 1 more Show less
2025.9.25
Fixed in
2025.12.18
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68143
PYSEC-2026-1621
GHSA-5cgr-j3jf-jw3v
Jul 07, 2026
mcp-server-git's unrestricted git_init tool allows repository creation at arbitrary filesystem locations
Low
Network
Low
None
In mcp-server-git versions prior to 2025.9.25, the git_init tool accepted arbitrary filesystem paths and created Git repositories without validating the target location. Unlike other tools which required an existing repository, git_init could operate on any directory accessible to the server process, making those directories eligible for subsequent git operations. The tool was removed entirely, as the server is intended to operate on existing repositories only. Users are advised to upgrade to 2025.9.25 or newer to remediate this issue. Thank you to https://hackerone.com/yardenporat for disclosure, @0dd for contributing the fix. Affected versions
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
2025.1.14
2025.7.1
Fixed in
2025.9.25
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.4.0
minor
4 CVEs
CVE-2026-27735
PYSEC-2026-2630
GHSA-vjqx-cfc4-9h6v
Jul 13, 2026
mcp-server-git : Path traversal in git_add allows staging files outside repository boundaries
Low
Network
Low
None
In mcp-server-git thanks https://hackerone.com/0dd-g for reporting and contributing the fix. Affected versions
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
2025.1.14
2025.11.25
2025.12.18
+ 2 more Show less
2025.7.1
2025.9.25
Fixed in
2026.1.14
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-68145
PYSEC-2026-1623
GHSA-j22h-9j4x-23w5
Jul 07, 2026
mcp-server-git has missing path validation when using --repository flag
Low
Network
Low
None
In mcp-server-git versions prior to 2025.12.18, when the server is started with the --repository flag to restrict operations to a specific repository path, it did not validate that repo_path arguments in subsequent tool calls were actually within that configured path. This could allow tool calls to operate on other repositories accessible to the server process. The fix adds path validation that resolves both the configured repository and the requested path (following symlinks) and verifies the requested path is within the allowed repository before executing any git operations. Users are advised to upgrade to 2025.12.18 to remediate this issue. Thank you to https://hackerone.com/yardenporat for reporting. Affected versions
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
2025.1.14
2025.11.25
2025.7.1
+ 1 more Show less
2025.9.25
Fixed in
2025.12.18
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68144
PYSEC-2026-1622
GHSA-9xwc-hfwc-8w59
Jul 07, 2026
mcp-server-git argument injection in git_diff and git_checkout functions allows overwriting local files
Low
Network
Low
None
In mcp-server-git versions prior to 2025.12.18, the git_diff and git_checkout functions passed user-controlled arguments directly to git CLI commands without sanitization. Flag-like values (e.g., Thank you to https://hackerone.com/yardenporat for reporting. Affected versions
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
2025.1.14
2025.11.25
2025.7.1
+ 1 more Show less
2025.9.25
Fixed in
2025.12.18
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68143
PYSEC-2026-1621
GHSA-5cgr-j3jf-jw3v
Jul 07, 2026
mcp-server-git's unrestricted git_init tool allows repository creation at arbitrary filesystem locations
Low
Network
Low
None
In mcp-server-git versions prior to 2025.9.25, the git_init tool accepted arbitrary filesystem paths and created Git repositories without validating the target location. Unlike other tools which required an existing repository, git_init could operate on any directory accessible to the server process, making those directories eligible for subsequent git operations. The tool was removed entirely, as the server is intended to operate on existing repositories only. Users are advised to upgrade to 2025.9.25 or newer to remediate this issue. Thank you to https://hackerone.com/yardenporat for disclosure, @0dd for contributing the fix. Affected versions
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
2025.1.14
2025.7.1
Fixed in
2025.9.25
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.3.0
minor
4 CVEs
CVE-2026-27735
PYSEC-2026-2630
GHSA-vjqx-cfc4-9h6v
Jul 13, 2026
mcp-server-git : Path traversal in git_add allows staging files outside repository boundaries
Low
Network
Low
None
In mcp-server-git thanks https://hackerone.com/0dd-g for reporting and contributing the fix. Affected versions
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
2025.1.14
2025.11.25
2025.12.18
+ 2 more Show less
2025.7.1
2025.9.25
Fixed in
2026.1.14
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-68145
PYSEC-2026-1623
GHSA-j22h-9j4x-23w5
Jul 07, 2026
mcp-server-git has missing path validation when using --repository flag
Low
Network
Low
None
In mcp-server-git versions prior to 2025.12.18, when the server is started with the --repository flag to restrict operations to a specific repository path, it did not validate that repo_path arguments in subsequent tool calls were actually within that configured path. This could allow tool calls to operate on other repositories accessible to the server process. The fix adds path validation that resolves both the configured repository and the requested path (following symlinks) and verifies the requested path is within the allowed repository before executing any git operations. Users are advised to upgrade to 2025.12.18 to remediate this issue. Thank you to https://hackerone.com/yardenporat for reporting. Affected versions
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
2025.1.14
2025.11.25
2025.7.1
+ 1 more Show less
2025.9.25
Fixed in
2025.12.18
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68144
PYSEC-2026-1622
GHSA-9xwc-hfwc-8w59
Jul 07, 2026
mcp-server-git argument injection in git_diff and git_checkout functions allows overwriting local files
Low
Network
Low
None
In mcp-server-git versions prior to 2025.12.18, the git_diff and git_checkout functions passed user-controlled arguments directly to git CLI commands without sanitization. Flag-like values (e.g., Thank you to https://hackerone.com/yardenporat for reporting. Affected versions
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
2025.1.14
2025.11.25
2025.7.1
+ 1 more Show less
2025.9.25
Fixed in
2025.12.18
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68143
PYSEC-2026-1621
GHSA-5cgr-j3jf-jw3v
Jul 07, 2026
mcp-server-git's unrestricted git_init tool allows repository creation at arbitrary filesystem locations
Low
Network
Low
None
In mcp-server-git versions prior to 2025.9.25, the git_init tool accepted arbitrary filesystem paths and created Git repositories without validating the target location. Unlike other tools which required an existing repository, git_init could operate on any directory accessible to the server process, making those directories eligible for subsequent git operations. The tool was removed entirely, as the server is intended to operate on existing repositories only. Users are advised to upgrade to 2025.9.25 or newer to remediate this issue. Thank you to https://hackerone.com/yardenporat for disclosure, @0dd for contributing the fix. Affected versions
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
2025.1.14
2025.7.1
Fixed in
2025.9.25
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.2.0
initial
4 CVEs
CVE-2026-27735
PYSEC-2026-2630
GHSA-vjqx-cfc4-9h6v
Jul 13, 2026
mcp-server-git : Path traversal in git_add allows staging files outside repository boundaries
Low
Network
Low
None
In mcp-server-git thanks https://hackerone.com/0dd-g for reporting and contributing the fix. Affected versions
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
2025.1.14
2025.11.25
2025.12.18
+ 2 more Show less
2025.7.1
2025.9.25
Fixed in
2026.1.14
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-68145
PYSEC-2026-1623
GHSA-j22h-9j4x-23w5
Jul 07, 2026
mcp-server-git has missing path validation when using --repository flag
Low
Network
Low
None
In mcp-server-git versions prior to 2025.12.18, when the server is started with the --repository flag to restrict operations to a specific repository path, it did not validate that repo_path arguments in subsequent tool calls were actually within that configured path. This could allow tool calls to operate on other repositories accessible to the server process. The fix adds path validation that resolves both the configured repository and the requested path (following symlinks) and verifies the requested path is within the allowed repository before executing any git operations. Users are advised to upgrade to 2025.12.18 to remediate this issue. Thank you to https://hackerone.com/yardenporat for reporting. Affected versions
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
2025.1.14
2025.11.25
2025.7.1
+ 1 more Show less
2025.9.25
Fixed in
2025.12.18
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68144
PYSEC-2026-1622
GHSA-9xwc-hfwc-8w59
Jul 07, 2026
mcp-server-git argument injection in git_diff and git_checkout functions allows overwriting local files
Low
Network
Low
None
In mcp-server-git versions prior to 2025.12.18, the git_diff and git_checkout functions passed user-controlled arguments directly to git CLI commands without sanitization. Flag-like values (e.g., Thank you to https://hackerone.com/yardenporat for reporting. Affected versions
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
2025.1.14
2025.11.25
2025.7.1
+ 1 more Show less
2025.9.25
Fixed in
2025.12.18
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68143
PYSEC-2026-1621
GHSA-5cgr-j3jf-jw3v
Jul 07, 2026
mcp-server-git's unrestricted git_init tool allows repository creation at arbitrary filesystem locations
Low
Network
Low
None
In mcp-server-git versions prior to 2025.9.25, the git_init tool accepted arbitrary filesystem paths and created Git repositories without validating the target location. Unlike other tools which required an existing repository, git_init could operate on any directory accessible to the server process, making those directories eligible for subsequent git operations. The tool was removed entirely, as the server is intended to operate on existing repositories only. Users are advised to upgrade to 2025.9.25 or newer to remediate this issue. Thank you to https://hackerone.com/yardenporat for disclosure, @0dd for contributing the fix. Affected versions
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
2025.1.14
2025.7.1
Fixed in
2025.9.25
References
Updated Jul 07, 2026 · Source: OSV.dev |