github.com/github/github-mcp-server is vulnerable to Improper Access Control
80
High Risk
Affected versions of this package are vulnerable due to incorrect authorization checks in lockdown mode. The original implementation relied on GraphQL collaborator-based authorization and contained flawed safety decision logic, missing explicit handling for trusted bots and lacking adequate nil guards in IsSafeContent. This could incorrectly determine push access or repository privacy, allowing malicious users to bypass content filtering under lockdown mode.
You are affected if you are using a version that falls within the vulnerable range.
github.com/github/github-mcp-server is vulnerable to Improper Access Control in versions 0.0.1 - 1.0.2.
Upgrade the github.com/github/github-mcp-server library to the patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant