Vulnerability in GitHub's MCP server leading to information leakage from private repositories.

A vulnerability has been identified in GitHub MCP Server, the implementation of the MCP (Model Context Protocol) by GitHub, which allows the extraction of data from users' private repositories that utilize AI assistants for repository automation.

The MCP protocol is designed to connect AI models with various data sources. GitHub MCP Server enables seamless integration of large language models with the GitHub API and provides these models with additional context by extracting data from GitHub repositories. Models utilizing MCP can be applied for automating specific actions on GitHub, such as parsing error messages.

The essence of the vulnerability lies in the fact that through interaction with a large language model linked to GitHub, one can obtain confidential user data tied to the account where the AI agent is connected. An attacker can create a specially crafted issue report in a public repository that uses automation based on the large language model. Upon activation, the model will generate a pull request with a proposed solution. Accordingly, if the issue pertains to private repositories or confidential data, the model may disclose information in the suggested pull request.

Vulnerability in GitHub's MCP server leading to information leakage from private repositories.

For example, an error message was sent complaining that the author was not specified in the README file. The proposed solution in the message was to add the author's information and a list of all repositories the author had worked on in the README. As a result, the model created a pull request containing information that included personal details about the author, extracted from a private repository, as well as a list of existing private repositories. In the next stage, similar interactions with the model could yield data from a specific private repository.

To activate the AI agent, the repository owner must issue a command to parse error messages. If GitHub is connected to the AI service Claude, it is sufficient for the repository owner to send a request to the AI assistant in the form of "look at the issues in my open source repositories and resolve them." After that, the AI assistant will utilize the configured MCP integration with the GitHub account and execute the instructions contained in the issue messages.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster