logo

Anthropic quietly fixed flaws in its Git MCP server that allowed for remote code execution

ID: 63f982f1-defb-58ad-b899-085894549a2c

STIX ID: report--63f982f1-defb-58ad-b899-085894549a2c

Feed Name: The Register (Security)

Threat Score
70/100

Date Published: 2026-01-20

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Anthropic patched three vulnerabilities in its mcp-server-git that Cyata researchers showed can be chained with the Filesystem MCP and prompt injection to access arbitrary repositories, create repositories in arbitrary locations, inject arguments into Git operations, overwrite files, and ultimately achieve remote code execution. The issues (CVE-2025-68143, CVE-2025-68144, CVE-2025-68145) affect default mcp-server-git deployments prior to 2025.12.18; Cyata disclosed the attack chain and Anthropic fixed the flaws, and there is no indication of active exploitation in the wild.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.