A critical vulnerability in the GitHub MCP server allows attackers to access private repository data by hijacking a user's agent via a malicious GitHub Issue. The vulnerability is not specific to any particular agent or MCP client and affects any agent that uses the GitHub MCP server. The attack can be triggered by a user querying their agent to look at issues in a public repository, which can lead to the agent fetching issues and getting injected with malicious code. This can result in the agent leaking private repository data into a public repository.