Command Injection Vulnerability in dvladimirov MCP Git Search API
CVE-2026-7211
Key Information:
- Vendor
Dvladimirov
- Status
- Vendor
- CVE Published:
- 28 April 2026
Badges
What is CVE-2026-7211?
A security flaw exists in the dvladimirov MCP Git Search API affecting versions up to 0.1.0. The vulnerability is located in the GitSearchRequest function of the mcp_server.py file. Through a manipulation of the 'repo_url/pattern' arguments, an attacker can execute remote command injection. The exploit code has been publicly shared, raising significant concerns about potential unauthorized access and operations on affected systems. Despite early notification of the issue via an issue report, the project maintainers have yet to address this vulnerability.
Affected Version(s)
MCP 0.1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
