{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3agit-mcp-servergit-mcp-server2.15.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:git-mcp-server:git-mcp-server:2.15.1:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-85626"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["git-mcp-server (2.15.1)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003egit-mcp-server version 2.15.1 contains an argument injection vulnerability within the ref and object parameters used by the git_log, git_diff, and git_show tools. The vulnerability arises because these parameters lack proper validation to prevent the inclusion of leading dashes, which are interpreted as command-line flags by the underlying git binary. An attacker who can influence these parameters can inject arbitrary git command-line arguments, such as the --output option. By controlling the output path, an attacker can coerce the process into writing files to unauthorized locations on the filesystem, provided those paths are accessible by the service account running the git-mcp-server process. This vulnerability (CVE-2026-85626) poses a significant risk for unauthorized file creation or overwriting, potentially leading to remote code execution or privilege escalation if sensitive configuration files or startup scripts are targeted.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows an unauthenticated or authenticated user with access to the MCP interface to perform arbitrary file writes. This can result in system compromise, data destruction, or the injection of malicious scripts that gain execution context under the user account running the git-mcp-server instance.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade to a version of git-mcp-server that addresses CVE-2026-85626, as no specific version is identified as patched in the current report, monitor vendor security advisories for the remediation release.\u003c/li\u003e\n\u003cli\u003eImplement strict input validation on the backend for all ref and object parameters to ensure they do not start with a dash character.\u003c/li\u003e\n\u003cli\u003eRun the git-mcp-server process with the least privilege necessary, restricting write access to the filesystem to only required directories.\u003c/li\u003e\n\u003cli\u003eMonitor process execution logs for instances where git child processes are spawned with unexpected command-line arguments, specifically the --output parameter.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-04T15:28:28Z","date_published":"2026-09-04T15:28:28Z","id":"https://feed.craftedsignal.io/briefs/2026-09-git-mcp-server-argument-injection/","summary":"git-mcp-server version 2.15.1 is vulnerable to argument injection due to insufficient input validation in the ref and object parameters of its git tools, allowing for arbitrary file writes.","title":"Argument Injection Vulnerability in git-mcp-server","url":"https://feed.craftedsignal.io/briefs/2026-09-git-mcp-server-argument-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:git-Mcp-Server:git-Mcp-Server:2.15.1:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}