
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27735 is a path traversal vulnerability in the git_add tool of mcp-server-git, a reference implementation for the Model Context Protocol (MCP). The flaw allows an attacker to stage files located outside the intended repository boundaries into the Git index by supplying relative paths containing ../ sequences. All versions of mcp-server-git prior to 2026.1.14 are affected. The vulnerability was reported via HackerOne by researcher 0dd-g, disclosed on February 25–26, 2026, and carries a CVSS v4.0 base score of 6.4 (Medium) and a CVSS v3.1 base score of 6.5 (Medium) (Github Advisory, GitHub Security Advisory).
The root cause is CWE-22 (Improper Limitation of a Pathname to a Restricted Directory — Path Traversal). The vulnerable git_add tool used GitPython's repo.index.add() API, which does not enforce working-tree boundary checks for relative paths; as a result, paths such as ../../etc/passwd passed in the files argument were accepted and staged into the Git index without validation. The fix, introduced in PR #3164, replaces the GitPython API call with repo.git.add(), which delegates to the Git CLI and properly rejects out-of-tree paths, including use of a -- separator to prevent option injection (Github Advisory, GitHub PR #3164). Exploitation requires user interaction (passive), meaning a user must invoke the git_add tool with attacker-influenced input, but no privileges are required (GitHub Security Advisory).
Successful exploitation allows an attacker to stage arbitrary files from outside the repository's working tree into the Git index. If a subsequent git commit and git push are performed — either by the user or an automated pipeline — sensitive files (e.g., credentials, private keys, configuration files) accessible to the process running mcp-server-git could be exfiltrated to a remote repository. The primary impact is high confidentiality and integrity loss on subsequent systems, while the directly vulnerable system itself is not directly impacted (Github Advisory, GitHub Security Advisory).
No public proof-of-concept exploit code is known to exist, and there is no evidence of active in-the-wild exploitation at this time (Github Advisory). The EPSS score is approximately 0.039% (12th percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.
mcp-server-git prior to version 2026.1.14 where the MCP server is accessible and the git_add tool can be invoked (e.g., via an AI agent or MCP client).../ sequences that traverses outside the repository root and points to a sensitive file on the host filesystem (e.g., ../../home/user/.ssh/id_rsa or ../../etc/shadow).git_add tool: Submit the crafted path as the files argument to the git_add MCP tool. Because the vulnerable code uses repo.index.add() without boundary validation, the file is accepted and staged into the Git index.git commit and git push, which transmits the staged out-of-tree file to the remote repository, completing the exfiltration (Github Advisory, GitHub PR #3164).git status or git diff --cached) that originate from outside the repository working directory; files with paths resolving to system directories (e.g., /etc/, /home/, ~/.ssh/) appearing in commit history.git_add tool invocations with arguments containing ../ sequences or absolute paths outside the repository root.mcp-server-git process to directories outside the designated repository path, observable via audit logs (e.g., Linux auditd with file-open rules on sensitive paths).Users should upgrade mcp-server-git to version 2026.1.14 or newer, which replaces the vulnerable repo.index.add() call with repo.git.add() to enforce proper path boundary validation via the Git CLI (Github Advisory, GitHub PR #3164). As an interim measure, restrict or disable the git_add tool in your MCP environment and review recent repository commits for any unexpectedly staged files. Implement input validation controls in your deployment to reject file paths containing ../ sequences before they reach the MCP server.
The vulnerability was reported by HackerOne researcher 0dd-g, who also contributed the fix via PR #3164, demonstrating responsible disclosure and community-driven remediation (Github Advisory). Broader commentary has emerged in the context of MCP security, with at least one publication noting that MCP security flaws are turning AI infrastructure into a supply chain risk (Startup Fortune). A technical blog post on MCP path traversal patterns was also published, reflecting growing researcher interest in this vulnerability class within AI tooling ecosystems.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."