A vulnerability categorized as problematic has been discovered in GitHub MCP Server up to 1.0.x. Impacted is the function
CompletionsHandler of the file pkg/github/server.go of the component Completion Handler. The manipulation of the argument Ref results in null pointer dereference.
This vulnerability is identified as CVE-2026-47427. The attack can be executed remotely. There is not any exploit available.
It is advisable to upgrade the affected component.