Junglewise Threat Intelligence

CVE-2026-27735: PYSEC-2026-2630 - mcp-server-git : Path traversal in git_add allows staging files outside repository boundaries

CVE-2026-27735 · Severity: medium · CVSS 4 · Published 2026-07-13

Technologies: mcp-server-git (PyPI). Vendors: PyPI.

Executive brief

mcp-server-git : Path traversal in git_add allows staging files outside repository boundaries

Affected products

  • PyPI mcp-server-git

Related threats