CVE-2026-85626 | cyanheads git-mcp-server up to 2.15.3 git_log/git_diff/git_show ref/object argument injection

SecurityVulns

A vulnerability classified as problematic was found in cyanheads git-mcp-server up to 2.15.3. This affects the function git_log/git_diff/git_show. Executing a manipulation of the argument ref/object can lead to argument injection.

This vulnerability appears as CVE-2026-85626. The attack may be performed from remote. There is no available exploit.VulDB Recent EntriesRead More