Prompt Injection Bugs Found in Official Anthropic Git MCP Server
ID: 2c6fda22-aa71-5801-88a4-f8e4b684999b
STIX ID: report--2c6fda22-aa71-5801-88a4-f8e4b684999b
Feed Name: Infosecurity Magazine (News)
Three vulnerabilities in Anthropic's mcp-server-git were discovered that allow attackers to use prompt injection (e.g., malicious README, poisoned issue) to manipulate AI assistants into performing unintended actions. The flaws permit code execution when combined with a filesystem MCP server, arbitrary file deletion, and loading arbitrary files into an LLM's context; they affect all versions released before 2025-12-08 on default installs. Cyata reported the issues, which received CVE-2025-68143, CVE-2025-68144 and CVE-2025-68145, and Anthropic released fixes in December 2025—users are advised to update and review MCP server combinations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
