CVE-2026-102906 Details
Description
A vulnerability was identified in 0xshariq github-mcp-server up to 52e764a7d66eac1726fce02ca7bb5a638571801a. This issue affects the function child_process.exec of the file src/github.ts of the component Git Remove MCP Tool. Such manipulation of the argument File leads to os command injection. The attack can be executed remotely. The exploit is publicly available and might be used. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. The project was informed of the problem early through an issue report but has not responded yet.
An OS command injection vulnerability has been identified in 0xshariq GitHub MCP Server, specifically in the 'git_remove' tool of the 'Git Remove MCP Tool' component. This vulnerability exists in the 'src/github.ts' file, up to commit '52e764a7d66eac1726fce02ca7bb5a638571801a'. The issue arises because the 'child_process.exec' function is used to execute commands, allowing remote attackers to inject and execute arbitrary operating system commands by manipulating the 'file' argument. The vulnerability has been reported to the project, but no response has been received yet.
It is recommended to replace 'child_process.exec' with 'child_process.execFile' or 'spawn', using 'shell: false' to prevent shell injection vulnerabilities. Additionally, implement checks to restrict the 'file' argument to repository-relative paths and require proper authorization for tools that modify repository data.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/0xshariq/github-mcp-server/ | [email protected] | ProductSource CodeVendor |
| https://github.com/0xshariq/github-mcp-server/issues/2 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://vuldb.com/cve/CVE-2026-102906 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/953767 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/411537 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/411537/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-77 | Improper Neutralization of Special Elements used in a Command ('Command Injection') | [email protected] |
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| 0xshariq github-mcp-server | <e3be2cc110ec0bb055a699a9b74cf20fe0422e3c |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 30, 2026 | New CVE Received | [email protected] |
Volerion