Loading the current evidence view. Navigation and account controls remain available.
Indicator investigation
Loading the current evidence view. Navigation and account controls remain available.
Loading verdict, provenance, relationships and sightings.
Indicator
Type cve · source NVD CVE
Grouped attempts with latest status; expand for attempt history.
2 attempts · first 2026-09-04T20:50:36.356477Z · last 2026-09-04T23:08:53.189367Z
Not listed in CISA KEV (local)
Types: cisa_kev
2 attempts · first 2026-09-04T20:50:36.361026Z · last 2026-09-04T23:08:53.195105Z
git-mcp-server 2.15.1 contains an argument injection vulnerability in the ref and object parameters of git_log, git_diff, and git_show tools that lack leading-dash validation. Attackers can inject git command-line options like --output= to write files outside the repository to arbitrary paths accessible by the process. · CWEs: CWE-88
Types: nvd_local
High-signal pivots without leaving the thread you started in search.
Structured pivots from local graph context.
Full investigation canvas with neighbor expansion.