Model Context Protocol Servers是Model Context Protocol开源的一个大模型上下文协议服务器。 Model Context Protocol Servers 2025.12.17之前版本存在路径遍历漏洞,该漏洞源于未验证后续工具调用中的repo_path参数是否在配置的路径内,可能导致对服务器进程可访问的其他仓库进行操作。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| modelcontextprotocol | servers | < 2025.12.17 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-68144 | mcp-server-git argument injection in git_diff and git_checkout functions allows overwritin | |
| CVE-2025-68143 | mcp-server-git's unrestricted git_init tool allows repository creation at arbitrary filesy |
No comments yet