MCP Watch has a Critical Command Injection in cloneRepo allows Remote Code Execution (RCE) via malicious URL
Critical severity
GitHub Reviewed
Published
Dec 1, 2025
in
kapilduraphe/mcp-watch
•
Updated Dec 2, 2025
Give feedback on Dependabot alerts