All 6 CVE vulnerabilities found in servers, with AI-generated Chinese analysis, references, and POCs.
Vendor: modelcontextprotocol
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-27735 | mcp-server-git : Path traversal in git_add allows staging files outside repository boundaries CWE-22 | 8.6AI | HighAI | 2026-02-25 |
| CVE-2025-68145 | mcp-server-git has missing path validation when using --repository flag CWE-22 | 9.8AI | CriticalAI | 2025-12-17 |
| CVE-2025-68144 | mcp-server-git argument injection in git_diff and git_checkout functions allows overwriting local files CWE-88 | 9.1AI | CriticalAI | 2025-12-17 |
| CVE-2025-68143 | mcp-server-git's unrestricted git_init tool allows repository creation at arbitrary filesystem locations CWE-22 | 9.1AI | CriticalAI | 2025-12-17 |
| CVE-2025-53109 | Model Context Protocol Servers Vulnerable to Path Validation Bypass via Prefix Matching and Symlink Handling CWE-59 | 4.3AI | MediumAI | 2025-07-02 |
| CVE-2025-53110 | Model Context Protocol Servers Vulnerable to Path Validation Bypass via Colliding Path Prefix CWE-22 | 7.5AI | HighAI | 2025-07-02 |
All 6 known CVE vulnerabilities affecting servers with full Chinese analysis, references, and POCs where available.