VendorsLF Projectsmodel_context_protocol_serversall versions
Vulnerabilities

LF Projects Lfprojects Model Context Protocol Servers

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2025-68145
mcp-server-git has missing path validation when using --repository flag
Published 2025-12-17 · Analyzed
9.1EPSS 0.070
CVE-2025-68143
mcp-server-git's unrestricted git_init tool allows repository creation at arbitrary filesystem locations
Published 2025-12-17 · Analyzed
8.8EPSS 0.081
CVE-2025-68144
mcp-server-git argument injection in git_diff and git_checkout functions allows overwriting local files
Published 2025-12-17 · Analyzed
7.1EPSS 0.072
CVE-2026-27735
mcp-server-git : Path traversal in git_add allows staging files outside repository boundaries
Published 2026-02-25 · Analyzed
6.5EPSS 0.003