git-mcp-server 2.15.1 contains an argument injection vulnerability in the ref and object parameters of gitlog, gitdiff, and git_show tools that lack leading-dash validation. Attackers can inject git command-line options like --output= to write files outside the repository to arbitrary paths accessible by the process.
{
"cwe_ids": [
"CWE-88"
],
"cna_assigner": "VulnCheck",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/85xxx/CVE-2026-85626.json"
}