Vulnerability  ·  2026-10-01

github-mcp-server Git Remove MCP tool OS command injection

VulnerabilityMedium impactGlobalCVE-2026-102906
NVD published (CVSS 6.3) an OS command injection in the File-handling path of a GitHub MCP server; classic unvalidated argument flowing into exec.
Adds to the recurring MCP-tool command-injection pattern; any agent connected to this server can be steered into host command execution. Narrow repo, no known active exploit.
The Git Remove MCP tool passes the File argument to child_process.exec, allowing OS command injection by an attacker who can invoke or steer the tool.
0xshariq github-mcp-server up to commit 52e764a7d66eac1726fce02ca7bb5a638571801a (src/github.ts, Git Remove MCP tool)
Update github-mcp-server past the affected commit; validate/sanitize tool arguments.
NVDgithub-mcp-server repository
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →