Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Artificial Intelligence

Anthropic MCP Server Flaws Lead to Code Execution, Data Exposure

Impacting Anthropic’s official MCP server, the vulnerabilities can be exploited through prompt injections.

AI hack

New research from Cyata reveals that flaws in the servers connecting LLMs to local data via Anthropic’s MCP can be exploited to achieve remote code execution and unauthorized file access.

All three flaws were identified in the official Git MCP server (mcp-server-git) maintained by Anthropic and could be exploited via prompt injections with attacker-controlled arguments.

“MCP servers execute actions based on LLM decisions, and LLMs can be manipulated through prompt injection,” Cyata explained. “A malicious actor who can influence the AI’s context can trigger MCP tool calls with attacker-controlled arguments.”

The bugs, tracked as CVE-2025-68143, CVE-2025-68145, and CVE-2025-68144, existed because the Git MCP server failed to validate or sanitize specific arguments provided by an attacker.

“These flaws can be exploited through prompt injection, meaning an attacker who can influence what an AI assistant reads (a malicious README, a poisoned issue description, a compromised webpage) can weaponize these vulnerabilities without any direct access to the victim’s system,” Cyata said.

The security firm’s researchers showed how an attacker could exploit the vulnerabilities for arbitrary code execution, reading files, and deleting files, with the attack working against any configuration. 

Advertisement. Scroll to continue reading.

The cybersecurity firm first reported the issues to Anthropic in June and July 2025.

The vendor resolved all three vulnerabilities in December, in mcp-server-git version 2025.12.18.

Related: Chainlit Vulnerabilities May Leak Sensitive Information

Related: Weaponized Invite Enabled Calendar Data Theft via Google Gemini

Related: LLMs in Attacker Crosshairs, Warns Threat Intel Firm

Related: WormGPT 4 and KawaiiGPT: New Dark LLMs Boost Cybercrime Automation

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

PNC Financial Services Group has appointed Christian Winward as CISO.

Brian Gumbel has joined Armadin as Chief Revenue Officer.

EigenQ has appointed Mark Pecen as Vice Chairman and Alexander Truskovsky as CISO.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.