Impact
A flaw has been found in versions of 0xshariq github‑mcp‑server where the child_process.exec function in src/github.ts accepts a File parameter that can be constructed by an attacker. This allows arbitrary OS command injection, giving the attacker the ability to execute any shell command on the host. The vulnerability is exploitation by remote actors and can lead to full compromise of the affected system, enabling data exfiltration, modification or destruction.
Affected Systems
The affected product is the Git Remove MCP Tool maintained under the 0xshariq github‑mcp‑server repository. All deployments that use any unreleased commit up to the vulnerable hash 52e764a7d66eac1726fce02ca7bb5a638571801a are susceptible. Because the project follows a rolling release model, the specific version numbers of affected releases are not published, and the project has yet to respond to the issue.
Risk and Exploitability
The CVSS score is 5.3, indicating a moderate level of severity, and the EPSS score is not available. Since the vulnerability is publicly documented and exploitable via remote input, the risk is amplified when the tool is exposed to the internet or untrusted users. The feature is not listed in the CISA KEV catalog, but the lack of output from the project suggests a potential window for exploitation. Administrators should treat this as a potential remote code execution threat when the tool is accessible over the network.
OpenCVE Enrichment