Anthropic, Microsoft MCP Server Flaws Shine a Light on AI Security Risks
ID: 1bb2b7f4-1f60-5d27-8a20-0e302c8db6bb
STIX ID: report--1bb2b7f4-1f60-5d27-8a20-0e302c8db6bb
Feed Name: Security Boulevard
Executive summary: Security researchers disclosed three CVEs in Anthropic’s Git MCP server that can be chained via prompt injection to read arbitrary filesystem content and achieve remote code execution, and a Server-Side Request Forgery (SSRF) vulnerability in Microsoft’s MarkItDown MCP tool that allows fetching arbitrary URIs (including cloud instance metadata), potentially exposing AWS credentials; research found tens of percent of discovered MCP servers exposed, highlighting urgent supply-chain and runtime security risks for AI agent tooling and the need to apply patches and zero-trust controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
