PT-2026-25573 · Hypermodel · Mcp-Server-Auto-Commit
Yinci Chen
·
Published
2026-03-15
·
Updated
2026-03-16
·
CVE-2026-4198
CVSS v3.1
5.3
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
hypermodel-labs mcp-server-auto-commit version 1.0.0
Description
A command injection issue exists in the
getGitChanges function within the index.ts file. This manipulation allows for local execution of commands. The exploit has been publicly disclosed.Recommendations
Apply patch f7d992c830c5f2ec5749852e66c0195e3ed7fe30 to resolve this issue.
Exploit
Fix
Special Elements Injection
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mcp-Server-Auto-Commit