Cointime

Download App
iOS & Android

Anthropic patched three high-risk vulnerabilities in the MCPGit server, involving arbitrary file access and remote code execution.

 according to The Hacker News, Cyata researchers disclosed that the mcp-server-git maintained by Anthropic has three serious security vulnerabilities (CVE-2025-68143/44/45), which can be exploited to perform path traversal and parameter injection, and even achieve remote code execution.

These vulnerabilities can be weaponized through prompt injection, and attackers only need to control the AI assistant to read malicious content to trigger the attack. The vulnerabilities were fixed in the September and December 2025 versions, the official team has removed the git_init tool and enhanced path validation, and users are advised to update to the latest version as soon as possible.

Comments

All Comments

Recommended for you