Anthropic fixes three critical vulnerabilities in the MCP Git server, involving arbitrary file access and remote code execution
Jan 21, 2026 09:52:57
According to The Hacker News, Cyata researchers have disclosed three critical security vulnerabilities (CVE-2025-68143/44/45) in the mcp-server-git maintained by Anthropic, which can be exploited for path traversal and parameter injection, potentially leading to remote code execution.
These vulnerabilities can be weaponized through prompt injection, allowing attackers to trigger the attack simply by controlling the AI assistant to read malicious content. The vulnerabilities have been patched in the versions released in September and December 2025, and the official has removed the git_init tool and enhanced path validation, recommending users to update to the latest version as soon as possible.
Latest News
ChainCatcher
1월 22, 2026 03:43:45
ChainCatcher
1월 22, 2026 03:32:43
ChainCatcher
1월 22, 2026 03:32:11
ChainCatcher
1월 22, 2026 03:32:11
ChainCatcher
1월 22, 2026 03:27:49












