Intel

AIKIDO-2026-10715

github.com/github/github-mcp-server is vulnerable to Improper Access Control

Improper Access Control Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.

80

High Risk

This Affects:

GOgithub.com/github/github-mcp-server
0.0.1 - 1.0.2
Fixed in 1.0.3
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable due to incorrect authorization checks in lockdown mode. The original implementation relied on GraphQL collaborator-based authorization and contained flawed safety decision logic, missing explicit handling for trusted bots and lacking adequate nil guards in IsSafeContent. This could incorrectly determine push access or repository privacy, allowing malicious users to bypass content filtering under lockdown mode.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

github.com/github/github-mcp-server is vulnerable to Improper Access Control in versions 0.0.1 - 1.0.2.

How to fix this

Upgrade the github.com/github/github-mcp-server library to the patch version.