CVE-2025-68143 affects Model Context Protocol (MCP) Servers, specifically mcp-server-git versions prior to 2025.9.25. The vulnerability stems from the git_init tool accepting arbitrary filesystem paths for Git repository creation without validation, allowing operations on any accessible directory. This vulnerability has a CVSS score of 6.5 (MEDIUM), indicating a network-based attack with low complexity and no user interaction required. Successful exploitation could lead to high impacts on confidentiality, integrity, and availability, as it allows for arbitrary file system access and subsequent Git operations. There is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), and it is not listed on the KEV catalog, suggesting no active exploitation. However, there is significant community discussion and media coverage, indicating high awareness of the vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2025.9.25CPE matchmatch criteria | cpe:2.3:a:lfprojects:model_context_protocol_servers:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.