Path Traversal Vulnerability in mcp-server-git by Model Context Protocol
CVE-2025-68145
What is CVE-2025-68145?
A path traversal vulnerability exists in the mcp-server-git when launched with the --repository flag, allowing unauthorized access to other repositories on the server. The issue arises from a failure to validate that paths for subsequent tool calls are restricted to the specified repository. This oversight permits potential operations on unintended repositories. A recent update introduces robust path validation, ensuring that all requested paths align with the permitted repository path. Users are recommended to upgrade to version 2025.12.17 to mitigate this security risk effectively.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
servers < 2025.12.17
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
