PYSEC-2026-1622
mcp-server-git argument injection in git_diff and git_checkout functions allows overwriting local files
Quick fix
PYSEC-2026-1622 — mcp-server-git: upgrade to the fixed version with the command below.
pip install --upgrade 'mcp-server-git>=2025.12.18'Details
In mcp-server-git versions prior to 2025.12.18, the git_diff and git_checkout functions passed user-controlled arguments directly to git CLI commands without sanitization. Flag-like values (e.g., `--output=/path/to/file` for `git_diff`) would be interpreted as command-line options rather than git refs, enabling arbitrary file overwrites. The fix adds validation that rejects arguments starting with - and verifies the argument resolves to a valid git ref via rev_parse before execution. Users are advised to update to 2025.12.18 resolve this issue.
Thank you to https://hackerone.com/yardenporat for reporting.
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 2025.12.18pip install --upgrade 'mcp-server-git>=2025.12.18'References
- https://github.com/modelcontextprotocol/servers/security/advisories/GHSA-9xwc-hfwc-8w59[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2025-68144[ADVISORY]
- https://github.com/modelcontextprotocol/servers[PACKAGE]
- https://pypi.org/project/mcp-server-git[PACKAGE]
- https://github.com/advisories/GHSA-9xwc-hfwc-8w59[ADVISORY]