Anthropic fixes three critical vulnerabilities in the MCP Git server, involving arbitrary file access and remote code execution

Jan 21, 2026 09:52:57

Share to

According to The Hacker News, Cyata researchers have disclosed three critical security vulnerabilities (CVE-2025-68143/44/45) in the mcp-server-git maintained by Anthropic, which can be exploited for path traversal and parameter injection, potentially leading to remote code execution.

These vulnerabilities can be weaponized through prompt injection, allowing attackers to trigger the attack simply by controlling the AI assistant to read malicious content. The vulnerabilities have been patched in the versions released in September and December 2025, and the official has removed the git_init tool and enhanced path validation, recommending users to update to the latest version as soon as possible.

Latest News

Recent Fundraising

More
$5M 1월 21
$9M 1월 21
-- 1월 20

New Tokens

More
1월 26
1월 23
1월 22

Latest Updates on 𝕏

More
1월 20
1월 20