git-mcp-server argument injection in git tools
git-mcp-server 2.15.1 contains an argument injection vulnerability in git_log, git_diff, and git_show tools that allows attackers to inject git command-line options and write files to arbitrary paths.
Disclosed 4 September 2026 · Record updated 13 September 2026
Impact
Attackers can inject git command-line options to write files outside the repository to arbitrary paths accessible by the process.
Our coverage
No articles linked to this incident yet.
Sources
- github.comhttps://github.com/advisories/GHSA-p58h-f635-vjjm
