Executive brief
Repomix is a tool that prepares code repositories for use with AI models. A security flaw in its Model Context Protocol (MCP) server allows AI assistants or other tool-callers to read sensitive local files (such as .json, .txt, or .md files) that should be protected. This bypasses the tool's built-in secret-scanning safeguards, potentially exposing credentials or private configuration data to the AI model or its users.
Technical details
A vulnerability exists in the Repomix MCP server where the 'attach_packed_output' and 'read_repomix_output' tools fail to enforce the 'runSecretLint()' safety check used by other file-reading tools. An attacker with the ability to invoke MCP tools can register an arbitrary local file (with .json, .txt, .md, or .xml extensions) as a 'packed output' without validation of the file's schema or content. Because the server does not verify if the file is a legitimate Repomix output and skips secret scanning during this specific workflow, sensitive information like API keys or configuration files can be exfiltrated. The fix in version 1.14.1 implements serve-time secret scanning for all attach-sourced outputs.
Affected products
- yamadashy repomix < 1.14.1
Timeline
- 2026-05-26: patched: Fix committed to repository
- 2026-05-27: advisory: GitHub Security Advisory published
- 2026-07-15: disclosed: CVE published to NVD