Anthropic Git MCP Server Vulnerabilities Involving Path Traversal and Argument Injection
ID: 6bd1c24c-08a1-5a8d-b984-d901708233ff
STIX ID: report--6bd1c24c-08a1-5a8d-b984-d901708233ff
Feed Name: SOCRadar Blog
Threat Score
Anthropic's reference mcp-server-git implementation contained three disclosed vulnerabilities (two path traversal flaws and one argument-injection issue) that researchers demonstrated can be abused via prompt injection to read or delete arbitrary files and, when combined with file-writing capabilities, achieve remote code execution; Anthropic patched the issues (removing a vulnerable tool and adding stricter path validation) and users should upgrade versions prior to 2025.12.18.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
