Anthropic quietly fixed flaws in its Git MCP server that allowed for remote code execution
ID: 63f982f1-defb-58ad-b899-085894549a2c
STIX ID: report--63f982f1-defb-58ad-b899-085894549a2c
Feed Name: The Register (Security)
Anthropic patched three vulnerabilities in its mcp-server-git that Cyata researchers showed can be chained with the Filesystem MCP and prompt injection to access arbitrary repositories, create repositories in arbitrary locations, inject arguments into Git operations, overwrite files, and ultimately achieve remote code execution. The issues (CVE-2025-68143, CVE-2025-68144, CVE-2025-68145) affect default mcp-server-git deployments prior to 2025.12.18; Cyata disclosed the attack chain and Anthropic fixed the flaws, and there is no indication of active exploitation in the wild.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
