Arbitrary Filesystem Path Vulnerability in Model Context Protocol Servers by Model Context Protocol
CVE-2025-68143
What is CVE-2025-68143?
The Model Context Protocol Servers contain a vulnerability within the git_init tool, which allows for arbitrary filesystem paths to be accepted and processed. This lack of validation leads to the creation of Git repositories in any directory accessible to the server process, which exposes these directories to further git operations. As a result, the tool has been removed to ensure that server operations are restricted to existing repositories only. Users are strongly encouraged to update to version 2025.9.25 or later to mitigate this issue and ensure the security of their systems.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
servers < 2025.9.25
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
