Artificial Intelligence

Anthropic MCP Server Flaws Lead to Code Execution, Data Exposure

Impacting Anthropic’s official MCP server, the vulnerabilities can be exploited through prompt injections.

AI hack

New research from Cyata reveals that flaws in the servers connecting LLMs to local data via Anthropic’s MCP can be exploited to achieve remote code execution and unauthorized file access.

All three flaws were identified in the official Git MCP server (mcp-server-git) maintained by Anthropic and could be exploited via prompt injections with attacker-controlled arguments.

“MCP servers execute actions based on LLM decisions, and LLMs can be manipulated through prompt injection,” Cyata explained. “A malicious actor who can influence the AI’s context can trigger MCP tool calls with attacker-controlled arguments.”

The bugs, tracked as CVE-2025-68143, CVE-2025-68145, and CVE-2025-68144, existed because the Git MCP server failed to validate or sanitize specific arguments provided by an attacker.

“These flaws can be exploited through prompt injection, meaning an attacker who can influence what an AI assistant reads (a malicious README, a poisoned issue description, a compromised webpage) can weaponize these vulnerabilities without any direct access to the victim’s system,” Cyata said.

The security firm’s researchers showed how an attacker could exploit the vulnerabilities for arbitrary code execution, reading files, and deleting files, with the attack working against any configuration. 

Advertisement. Scroll to continue reading.

The cybersecurity firm first reported the issues to Anthropic in June and July 2025.

The vendor resolved all three vulnerabilities in December, in mcp-server-git version 2025.12.18.

Related: Chainlit Vulnerabilities May Leak Sensitive Information

Related: Weaponized Invite Enabled Calendar Data Theft via Google Gemini

Related: LLMs in Attacker Crosshairs, Warns Threat Intel Firm

Related: WormGPT 4 and KawaiiGPT: New Dark LLMs Boost Cybercrime Automation

Related Content

Vulnerabilities

The N‑central vulnerability CVE-2026-18577 has been exploited in the wild after threat actors found a patch bypass.

Ransomware

The INC Ransomware gang has been targeting vulnerable SMA1000 appliances for root access and lateral movement.

Vulnerabilities

The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE).

Artificial Intelligence

The internet giant has built an agent harness to find vulnerabilities across Chrome’s codebase.

Artificial Intelligence

When the AI Act comes into force, AI companies will be required to make clear to consumers with labels or digital watermarks that chatbots...

Artificial Intelligence

A security company’s systems were hacked after it installed a malicious Python package deployed by Claude. 

Vulnerabilities

Tracked as CVE-2026-63077, the security defect can be exploited without authentication via the agent polling protocol.

Artificial Intelligence

The best compliance programs aren't the biggest ones. They're the ones built on a short list of questions that can actually be answered, and...

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version