Describe the bug
The hosted GitHub MCP Server tool check_dependency_vulnerabilities appears to return only high-severity advisories while silently omitting applicable medium-severity advisories.
This can produce a misleading result such as 0 vulnerable or No known vulnerabilities found for package versions that the GitHub Advisory Database identifies as vulnerable. Consumers using the tool to verify dependency safety can therefore receive an incomplete result without any indication that a severity filter was applied.
The tool is available through the hosted endpoint at https://api.githubcopilot.com/mcp/. It does not appear in the public source or Git history of this repository. The repository's remote-server documentation notes that the hosted server binds this repository into GitHub infrastructure through an internal repository and may provide additional hosted-only tools.
Affected version
Hosted remote GitHub MCP Server at https://api.githubcopilot.com/mcp/, reproduced on October 6, 2026.
The hosted service does not expose a server version through this tool. This is not reproducible through the published local Docker image because check_dependency_vulnerabilities is a hosted-only tool.
Steps to reproduce the behavior
-
Connect to the hosted GitHub MCP Server at https://api.githubcopilot.com/mcp/ with access to the check_dependency_vulnerabilities tool.
-
Invoke the tool with this public repository and these dependencies:
{
"owner": "github",
"repo": "github-mcp-server",
"dependencies": [
{
"ecosystem": "npm",
"name": "yargs-parser",
"version": "9.0.2"
},
{
"ecosystem": "npm",
"name": "uuid",
"version": "8.0.0"
},
{
"ecosystem": "npm",
"name": "lodash",
"version": "4.17.20"
}
]
}
-
Observe that only the two high-severity lodash advisories are returned. No vulnerability is reported for yargs-parser@9.0.2 or uuid@8.0.0.
-
Query the GitHub Advisory Database with the same affected package versions:
gh api --method GET /advisories \
-f ecosystem=npm \
-f 'affects=yargs-parser@9.0.2' \
--jq '.[] | select(.withdrawn_at == null) | {ghsa_id,severity}'
gh api --method GET /advisories \
-f ecosystem=npm \
-f 'affects=uuid@8.0.0' \
--jq '.[] | select(.withdrawn_at == null) | {ghsa_id,severity}'
-
Observe the applicable non-withdrawn medium-severity advisories:
{"ghsa_id":"GHSA-p9pc-299p-vxgp","severity":"medium"}
{"ghsa_id":"GHSA-w5hq-g745-h8pq","severity":"medium"}
As a control, querying lodash@4.17.20 directly returns two high and three non-withdrawn medium advisories. The checker returns exactly the two high advisories and omits all three medium advisories.
Expected vs actual behavior
Expected:
check_dependency_vulnerabilities should return every applicable advisory, or accept and clearly document an explicit severity threshold. If results are intentionally filtered, the response should identify the effective threshold and must not state No known vulnerabilities found without qualification.
For this request, the result should include at least:
yargs-parser@9.0.2: GHSA-p9pc-299p-vxgp (medium), vulnerable range >= 6.0.0, < 13.1.2
uuid@8.0.0: GHSA-w5hq-g745-h8pq (medium), vulnerable range < 11.1.1
- The applicable high and medium advisories for
lodash@4.17.20
Actual:
The checker reports only the two high-severity lodash advisories and treats the two medium-severity dependencies as not vulnerable. The response gives no indication that medium and lower severities were excluded.
Logs
Actual hosted-tool output from the reproduction:
Dependency Vulnerability Report for github/github-mcp-server
Checked 3 dependency(ies). 1 vulnerable.
⚠ lodash@4.17.20 (npm) — 2 vulnerability(ies) found
- GHSA-r5fr-rjxr-66jc [high]: lodash vulnerable to Code Injection via `_.template` imports key names
→ Upgrade to 4.18.0 to mitigate
- GHSA-35jh-r3h4-6jhm [high]: Command Injection in lodash
→ Upgrade to 4.17.21 to mitigate
Found 2 total vulnerability(ies) across 1 dependency(ies)
The public list_global_security_advisories tool on the same hosted MCP server returns the omitted medium advisories when called without a severity filter. In the public implementation, the severity argument is optional and is only forwarded when explicitly provided:
|
"severity": { |
|
Type: "string", |
|
Description: "Filter by severity.", |
|
Enum: []any{"unknown", "low", "medium", "high", "critical"}, |
|
}, |
|
opts := &github.ListGlobalSecurityAdvisoriesOptions{} |
|
|
|
if ghsaID != "" { |
|
opts.GHSAID = &ghsaID |
|
} |
|
if typ != "" { |
|
opts.Type = &typ |
|
} |
|
if cveID != "" { |
|
opts.CVEID = &cveID |
|
} |
|
if eco != "" { |
|
opts.Ecosystem = &eco |
|
} |
|
if sev != "" { |
|
opts.Severity = &sev |
|
} |
|
if len(cwes) > 0 { |
|
opts.CWEs = cwes |
|
} |
|
|
|
if isWithdrawn { |
|
opts.IsWithdrawn = &isWithdrawn |
|
} |
|
|
|
if affects != "" { |
|
opts.Affects = &affects |
|
} |
|
if published != "" { |
|
opts.Published = &published |
|
} |
|
if updated != "" { |
|
opts.Updated = &updated |
|
} |
|
if modified != "" { |
|
opts.Modified = &modified |
|
} |
|
|
|
advisories, resp, err := client.SecurityAdvisories.ListGlobalSecurityAdvisories(ctx, opts) |
This evidence suggests the filtering occurs in the hosted-only check_dependency_vulnerabilities wrapper or its post-query processing rather than in the public advisory API wrapper.
Describe the bug
The hosted GitHub MCP Server tool
check_dependency_vulnerabilitiesappears to return only high-severity advisories while silently omitting applicable medium-severity advisories.This can produce a misleading result such as
0 vulnerableorNo known vulnerabilities foundfor package versions that the GitHub Advisory Database identifies as vulnerable. Consumers using the tool to verify dependency safety can therefore receive an incomplete result without any indication that a severity filter was applied.The tool is available through the hosted endpoint at
https://api.githubcopilot.com/mcp/. It does not appear in the public source or Git history of this repository. The repository's remote-server documentation notes that the hosted server binds this repository into GitHub infrastructure through an internal repository and may provide additional hosted-only tools.Affected version
Hosted remote GitHub MCP Server at
https://api.githubcopilot.com/mcp/, reproduced on October 6, 2026.The hosted service does not expose a server version through this tool. This is not reproducible through the published local Docker image because
check_dependency_vulnerabilitiesis a hosted-only tool.Steps to reproduce the behavior
Connect to the hosted GitHub MCP Server at
https://api.githubcopilot.com/mcp/with access to thecheck_dependency_vulnerabilitiestool.Invoke the tool with this public repository and these dependencies:
{ "owner": "github", "repo": "github-mcp-server", "dependencies": [ { "ecosystem": "npm", "name": "yargs-parser", "version": "9.0.2" }, { "ecosystem": "npm", "name": "uuid", "version": "8.0.0" }, { "ecosystem": "npm", "name": "lodash", "version": "4.17.20" } ] }Observe that only the two high-severity lodash advisories are returned. No vulnerability is reported for
yargs-parser@9.0.2oruuid@8.0.0.Query the GitHub Advisory Database with the same affected package versions:
Observe the applicable non-withdrawn medium-severity advisories:
{"ghsa_id":"GHSA-p9pc-299p-vxgp","severity":"medium"} {"ghsa_id":"GHSA-w5hq-g745-h8pq","severity":"medium"}As a control, querying
lodash@4.17.20directly returns two high and three non-withdrawn medium advisories. The checker returns exactly the two high advisories and omits all three medium advisories.Expected vs actual behavior
Expected:
check_dependency_vulnerabilitiesshould return every applicable advisory, or accept and clearly document an explicit severity threshold. If results are intentionally filtered, the response should identify the effective threshold and must not stateNo known vulnerabilities foundwithout qualification.For this request, the result should include at least:
yargs-parser@9.0.2:GHSA-p9pc-299p-vxgp(medium), vulnerable range>= 6.0.0, < 13.1.2uuid@8.0.0:GHSA-w5hq-g745-h8pq(medium), vulnerable range< 11.1.1lodash@4.17.20Actual:
The checker reports only the two high-severity lodash advisories and treats the two medium-severity dependencies as not vulnerable. The response gives no indication that medium and lower severities were excluded.
Logs
Actual hosted-tool output from the reproduction:
The public
list_global_security_advisoriestool on the same hosted MCP server returns the omitted medium advisories when called without a severity filter. In the public implementation, the severity argument is optional and is only forwarded when explicitly provided:github-mcp-server/pkg/github/security_advisories.go
Lines 53 to 57 in bf0f67f
github-mcp-server/pkg/github/security_advisories.go
Lines 150 to 188 in bf0f67f
This evidence suggests the filtering occurs in the hosted-only
check_dependency_vulnerabilitieswrapper or its post-query processing rather than in the public advisory API wrapper.