What happened
NVD published (CVSS 6.3) an OS command injection in the File-handling path of a GitHub MCP server; classic unvalidated argument flowing into exec.
Why it matters
Adds to the recurring MCP-tool command-injection pattern; any agent connected to this server can be steered into host command execution. Narrow repo, no known active exploit.
Attack vector
The Git Remove MCP tool passes the File argument to child_process.exec, allowing OS command injection by an attacker who can invoke or steer the tool.
Affected systems
0xshariq github-mcp-server up to commit 52e764a7d66eac1726fce02ca7bb5a638571801a (src/github.ts, Git Remove MCP tool)
Mitigation
Update github-mcp-server past the affected commit; validate/sanitize tool arguments.