Arbitrary Argument Injection Affecting mcp-server-git package, versions <2026.7.10-r0


Severity

Recommended
0.0
high
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
7.21% (94th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-MINIMOSLATEST-MCPSERVERGIT-17941713
  • published11 Jul 2026
  • disclosed17 Dec 2025

Introduced: 17 Dec 2025

CVE-2025-68144  (opens in a new tab)
CWE-88  (opens in a new tab)

How to fix?

Upgrade Minimos:latest mcp-server-git to version 2026.7.10-r0 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream mcp-server-git package and not the mcp-server-git package as distributed by Minimos. See How to fix? for Minimos:latest relevant fixed versions and status.

In mcp-server-git versions prior to 2025.12.17, the git_diff and git_checkout functions passed user-controlled arguments directly to git CLI commands without sanitization. Flag-like values (e.g., --output=/path/to/file for git_diff) would be interpreted as command-line options rather than git refs, enabling arbitrary file overwrites. The fix adds validation that rejects arguments starting with - and verifies the argument resolves to a valid git ref via rev_parse before execution. Users are advised to update to 2025.12.17 resolve this issue when it is released.

CVSS Base Scores

version 3.1