mcp-server-git vulnerabilities
CVEs whose affected-version data names the mcp-server-git package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
4 CVEsRSS
CVE-2026-27735Mediummcp-server-git : Path traversal in git_add allows staging files outside repository boundaries
mcp-server-git : Path traversal in git_add allows staging files outside repository boundaries
▾ Sunlitmcp-server-git · mcp-server-gitEPSS 0.29%via OSV
CVE-2025-68145Mediummcp-server-git has missing path validation when using --repository flag
mcp-server-git has missing path validation when using --repository flag
▾ Sunlitmcp-server-git · mcp-server-gitEPSS 7.0%via OSV
CVE-2025-68144Mediummcp-server-git argument injection in git_diff and git_checkout functions allows overwriting local files
mcp-server-git argument injection in git_diff and git_checkout functions allows overwriting local files
▾ Sunlitmcp-server-git · mcp-server-gitEPSS 7.2%via OSV
CVE-2025-68143Mediummcp-server-git's unrestricted git_init tool allows repository creation at arbitrary filesystem locations
mcp-server-git's unrestricted git_init tool allows repository creation at arbitrary filesystem locations
▾ Sunlitmcp-server-git · mcp-server-gitEPSS 8.1%via OSV