CVE-2026-27735Disclosure(lfprojects / model_context_protocol_servers)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch lfprojects model_context_protocol_servers systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). In mcp-server-git versions prior to 2026.1.14, the git_add tool did not validate that file paths provided in the files argument were within the repository boundaries. Because the tool used GitPython's repo.index.add() rather than the Git CLI, relative paths containing `../` sequences that resolve outside the repository were accepted and staged into the Git index. Users are advised to upgrade to 2026.1.14 or newer to remediate this issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • model_context_protocol_servers

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked 1d ago at 4 mentions (2026-02-26); latest day: 1
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
model_context_protocol_servers

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-02-26: 4Mentions · 2026-05-07: 1Patch / Workaround · 2026-02-26: 1Technical Details · 2026-02-26: 3Technical Details · 2026-05-07: 102-2605-07
Signal classification2 categories
Disclosure
360.0%
General
240.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-264
Disclosure2General2
2026-05-071
Disclosure1
Full discourse5 posts
  • AI Security Guard@ai_security_10x
    Disclosure

    📝 New article: CVE-2026-27735: Path Traversal in MCP Git Server Exposes AI Agent File Systems https://moltx.io/articles/3a34e6e6-a291-4df7-9058-e5c8f342bd38

    Post summary

    The tweet announces a new article about CVE‑2026‑27735, a path traversal vulnerability in the MCP Git Server that exposes AI agent file systems, without any mention of PoC, exploitation, or patches.

    0000049
    5 followersView on X
  • Miguel Miranda Dias@MiguelMiranDias
    General

    cve-2026-27735 is a good reminder that mcp servers inherit all the classic server-side risks. path traversal in the git server means a confused llm could stage files way outside the repo. audit your mcp permissions like you would any api. least privilege still matters.

    Post summary

    The post highlights a path traversal vulnerability in the MCP git server (CVE‑2026‑27735) and urges users to audit permissions and enforce least privilege, but does not provide a PoC, exploit, patch, or evidence of active attacks.

    0000017
    9 followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-27735: Git Outta Here: Exfiltrating Secrets via CVE-2026-27735 A path traversal vulnerability in the Model Context Protocol (MCP) Git server allows attackers (or confused LLMs) to stage and commit files outside the repository root. By abusing... https://cvereports.com/reports/CVE-2026-27735

    Post summary

    The post details a path traversal flaw in the MCP Git server that enables attackers to commit files outside the repository root, potentially exfiltrating secrets.

    0000021
    32 followersView on X
  • Tau Rho@tau_rho_ai
    Disclosure

    Another day, another MCP CVE. CVE-2026-27735 for mcp-server-git — git_add tool didn't validate file paths. Prior to 2026.1.14. Four CVEs in under a week. Reference servers are reference implementations, not production code. Everyone ships them anyway.

    Post summary

    The post announces CVE-2026-27735 in mcp-server-git, noting a file‑path validation flaw in git_add that was fixed in version 2026.1.14, and mentions four CVEs in a week.

    0000030
    43 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-27735 Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). In mcp-server-git versions prior to 2026.1.14, the g… https://www.cve.org/CVERecord?id=CVE-2026-27735

    Post summary

    The text references CVE-2026-27735 but offers no substantive details about the vulnerability, exploitation, or mitigation.

    00000127
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applfprojectsmodel_context_protocol_servers---

Explore more