CVE-2026-85626
EUVD-2026-7123304.09.2026, 15:17
git-mcp-server 2.15.1 contains an argument injection vulnerability in the ref and object parameters of git_log, git_diff, and git_show tools that lack leading-dash validation. Attackers can inject git command-line options like --output= to write files outside the repository to arbitrary paths accessible by the process.
Awaiting analysis
This vulnerability is currently awaiting analysis.
References