logo

Anthropic Git MCP Server Vulnerabilities Involving Path Traversal and Argument Injection

ID: 6bd1c24c-08a1-5a8d-b984-d901708233ff

STIX ID: report--6bd1c24c-08a1-5a8d-b984-d901708233ff

Feed Name: SOCRadar Blog

Threat Score
65/100

Date Published: 2026-01-21

Date Updated: 2026-04-30

Author: Ameer Owda

...
...

Anthropic's reference mcp-server-git implementation contained three disclosed vulnerabilities (two path traversal flaws and one argument-injection issue) that researchers demonstrated can be abused via prompt injection to read or delete arbitrary files and, when combined with file-writing capabilities, achieve remote code execution; Anthropic patched the issues (removing a vulnerable tool and adding stricter path validation) and users should upgrade versions prior to 2025.12.18.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.