CVE-2025-68143
Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). In mcp-server-git versions prior to 2025.9.25, the git_init tool accepted arbitrary filesystem paths and created Git repositories without validating the target location. Unlike other tools which required an existing repository, git_init could operate on any directory accessible to the server process, making those directories eligible for subsequent git operations. The tool was removed entirely, as the server is intended to operate on existing repositories only. Users are advised to upgrade to 2025.9.25 or newer to remediate this issue.
Published:Dec 17, 2025
Last Modified:Apr 14, 2026
EPS:Dec 17, 2025
EPSS Score:0.00156
CVSS Score:8.8
Affected Products
Vendor
Product
Action
Vendor
Lfprojects
Product
Model Context Protocol Servers
Lfprojects
Model Context Protocol Servers
Vendor
Modelcontextprotocol
Product
Servers
Modelcontextprotocol
Servers
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
