A vulnerability categorized as problematic has been discovered in GitHub MCP Server up to 1.0.x. Impacted is the function CompletionsHandler of the file pkg/github/server.go of the component Completion Handler. The manipulation of the argument Ref results in null pointer dereference.

This vulnerability is identified as CVE-2026-47427. The attack can be executed remotely. There is not any exploit available.

It is advisable to upgrade the affected component.