logo

Anthropic, Microsoft MCP Server Flaws Shine a Light on AI Security Risks

ID: 1bb2b7f4-1f60-5d27-8a20-0e302c8db6bb

STIX ID: report--1bb2b7f4-1f60-5d27-8a20-0e302c8db6bb

Feed Name: Security Boulevard

Threat Score
75/100

Date Published: 2026-01-23

Date Updated: 2026-04-22

Author: Jeffrey Burt

...
...

Executive summary: Security researchers disclosed three CVEs in Anthropic’s Git MCP server that can be chained via prompt injection to read arbitrary filesystem content and achieve remote code execution, and a Server-Side Request Forgery (SSRF) vulnerability in Microsoft’s MarkItDown MCP tool that allows fetching arbitrary URIs (including cloud instance metadata), potentially exposing AWS credentials; research found tens of percent of discovered MCP servers exposed, highlighting urgent supply-chain and runtime security risks for AI agent tooling and the need to apply patches and zero-trust controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.