CVE Explorer
CVE-2025-68143
Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). In mcp-server-git versions prior to 2025.9.25, the git_init tool accepted arbitrary filesystem paths and created Git repositories without validating the target location. Unlike other tools which required an existing repository, git_init could operate on any directory accessible to the server process, making those directories eligible for subsequent git operations. The tool was remove
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"servers","vendor":"modelcontextprotocol","versions":[{"status":"affected","version":"< 2025.9.25"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:7d3ac353585fbb9e6ead68fabf7ef5e60c75e6c077260c02df10334965f1d952 · sha256:e77f883503c07848… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":6.5,"baseSeverity":"MEDIUM","privilegesRequired":"NONE","subAvailabilityImpact":"HIGH","subConfidentialityImpact":"HIGH","subIntegrityImpact":"HIGH","userInteraction":"PASSIVE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:7d3ac353585fbb9e6ead68fabf7ef5e60c75e6c077260c02df10334965f1d952 · sha256:e77f883503c07848… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-22","description":"CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:7d3ac353585fbb9e6ead68fabf7ef5e60c75e6c077260c02df10334965f1d952 · sha256:e77f883503c07848… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"https://github.com/modelcontextprotocol/servers/commit/eac56e7bcde48fb64d5a973924d05d69a7d876e6","tags":["x_refsource_MISC"],"url":"https://github.com/modelcontextprotocol/servers/commit/eac56e7bcde48fb64d5a973924d05d69a7d876e6"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:7d3ac353585fbb9e6ead68fabf7ef5e60c75e6c077260c02df10334965f1d952 · sha256:e77f883503c07848… · /containers/cna/references/1
{"name":"https://github.com/modelcontextprotocol/servers/security/advisories/GHSA-5cgr-j3jf-jw3v","tags":["x_refsource_CONFIRM"],"url":"https://github.com/modelcontextprotocol/servers/security/advisories/GHSA-5cgr-j3jf-jw3v"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:7d3ac353585fbb9e6ead68fabf7ef5e60c75e6c077260c02df10334965f1d952 · sha256:e77f883503c07848… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.