CVE-2026-102906 github-mcp-server 操作系统命令注入漏洞
影响攻击者可远程执行任意操作系统命令
0xshariq github-mcp-server 的 Git Remove MCP Tool 组件在 src/github.ts 中调用 child_process.exec 时未对 File 参数做充分过滤,导致操作系统命令注入。该漏洞可远程利用,且已有公开的利用代码。项目采用滚动发布模式,受影响或修复版本信息无法确定。
影响范围
受影响版本为 0xshariq github-mcp-server 至提交 52e764a7d66eac1726fce02ca7bb5a638571801a;由于采用滚动发布,暂无公开的具体版本范围信息。
漏洞详情
漏洞类型为操作系统命令注入(OS Command Injection)。成因是 Git Remove MCP Tool 在处理 File 参数时直接将其拼接到 child_process.exec 执行的命令中,未进行转义或白名单校验。攻击者可通过构造恶意 File 值注入 shell 元字符,从而在目标主机上执行任意命令。
利用条件与风险
利用需攻击者能向该 MCP 工具传入可控的 File 参数,通常经由远程调用触发;由于利用代码已公开,实战中被扫描和利用的风险较高。
修复建议
官方尚未发布修复版本或回应,建议关注项目仓库更新;临时缓解措施包括避免将不可信输入传入该工具、对 File 参数做严格校验与转义,或改用不经过 shell 的执行方式(如 execFile)。
A vulnerability was identified in 0xshariq github-mcp-server up to 52e764a7d66eac1726fce02ca7bb5a638571801a. This issue affects the function child_process.exec of the file src/github.ts of the component Git Remove MCP Tool. Such manipulation of the argument File leads to os command injection. The attack can be executed remotely. The exploit is publicly available and might be used. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. The project was informed of the problem early through an issue report but has not responded yet.