Vulnerability in mcp-server-git Affects Multiple Versions
CVE-2025-68144
What is CVE-2025-68144?
In versions of mcp-server-git released before 2025.12.17, the git_diff and git_checkout functions inadequately handle user-controlled arguments, directly passing them to git CLI commands without proper sanitization. This oversight means that flag-like values, such as --output=/path/to/file for git_diff, could be interpreted as command-line options. This can result in arbitrary file overwrites. The mitigation introduced ensures that arguments starting with '-' are rejected, and validates that the argument resolves to a valid git reference via rev_parse before execution. Users are strongly encouraged to update to version 2025.12.17 upon its release to safeguard their systems.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
servers < 2025.12.17
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
