Anthropic fixed three vulnerabilities in its official Git MCP server (mcp-server-git) that could be triggered via prompt injection and chained with other MCP tools to achieve remote code execution or destructive file operations. The issues were reported by agentic AI security firm Cyata, which demonstrated that attacker-controlled content an AI assistant might read (for example, a malicious README, poisoned issue text, or other untrusted context) could drive the LLM to invoke MCP tool calls with crafted arguments, enabling exploitation without the attacker having direct access to the victim host.
Cyata identified CVE-2025-68143 (unrestricted git_init), CVE-2025-68145 (path validation bypass), and CVE-2025-68144 (argument injection in git_diff). In combination—particularly when mcp-server-git is used alongside the Filesystem MCP server—the flaws could enable code execution, arbitrary file deletion/overwrite, and reading arbitrary files into the LLM context (with Cyata noting this does not inherently provide direct exfiltration). The vulnerabilities affected default deployments of mcp-server-git prior to version 2025.12.18; Anthropic was notified in June and shipped fixes in December, and there was no indication reported that the bugs were exploited in the wild.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Multiple outlets reported that Anthropic had quietly fixed three critical vulnerabilities in its official Git MCP server and that there was no indication of in-the-wild exploitation. Coverage emphasized the risks of prompt injection and cross-tool chaining in agentic AI environments.
Cyata published research showing how the three vulnerabilities could be chained with filesystem-writing capabilities to enable arbitrary file overwrite and code execution via indirect prompt injection. The disclosure described abuse of Git clean/smudge filters and warned that MCP tool chaining creates broader ecosystem risk.
Anthropic committed the remaining fixes in December 2025, with reporting indicating default deployments prior to version 2025.12.18 were affected. Users were advised to upgrade to version 2025.12.18 or later.
Anthropic addressed part of the reported issues in mcp-server-git version 2025.9.25, including removing the git_init capability referenced in later reporting. This was one of the remediation steps for the disclosed vulnerability set.
Cyata responsibly disclosed three flaws in Anthropic's official Git MCP server in June 2025. The issues involved repository path validation bypasses and unsafe argument handling that could be triggered through prompt injection.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcethehackernews.com
Open sourcego.theregister.com
Open sourcecyata.ai
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.