Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Interview: Shopify CISO Andrew Dunbar on Securing an E-Commerce Giant

June 26, 2026

New CISA Guide Helps Agencies Adopt SASE For Zero Trust

June 25, 2026

Microsoft Confirms RoguePlanet Defender Zero-Day, Says Patch is in Development

June 25, 2026
Facebook X (Twitter) Instagram
Friday, June 26
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»Cyber Security»Prompt Injection Bugs Found in Official Anthropic Git MCP Server
Cyber Security

Prompt Injection Bugs Found in Official Anthropic Git MCP Server

Team-CWDBy Team-CWDJanuary 20, 2026No Comments2 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


Three security vulnerabilities in the official Git server for Anthropic’s Model Context Protocol (MCP), mcp-server-git, have been identified by cybersecurity researchers.

The flaws can be exploited through prompt injection, allowing attackers to manipulate AI assistants into performing unintended actions without needing direct access to a target system.

The issues affect all versions of mcp-server-git released before December 8, 2025, and apply to default installations.

According to cybersecurity firm Cyata, who discovered the flaws, an attacker only needs to influence what an AI assistant reads, such as a malicious README file, a poisoned issue description or a compromised webpage, to trigger the vulnerabilities. No credentials or system access are required.

The flaws allow attackers to execute code when mcp-server-git is used alongside a filesystem MCP server, delete arbitrary files and load arbitrary files into a large language model’s context. While the vulnerabilities do not directly exfiltrate data, sensitive files may still be exposed to the AI, creating downstream security and privacy risks.

The findings are notable because they affect Anthropic’s reference MCP implementation.

Previous MCP-related issues typically relied on unusual configurations or unsafe deployments. In this case, Cyata found that the vulnerabilities worked “out of the box,” increasing the likelihood of real-world impact.

Read more on Anthropic vulnerabilities: Claude Desktop Extensions Vulnerable to Web-Based Prompt Injection

Why the MCP Design Raises Risk

MCP is an open standard introduced by Anthropic in November 2024 to allow AI assistants to interact with tools such as filesystems, APIs, databases and developer utilities like Git. MCP servers act as a bridge, executing real system actions based on decisions made by large language models.

Cyata’s research showed that mcp-server-git does not properly validate repository paths or sanitise arguments passed to Git commands.

As a result, an attacker can direct the server to operate on any directory on the system, not just the repository defined in its configuration. In one case, unsanitized arguments to the git_diff command allow attackers to overwrite files. In others, misuse of git_init enables file deletion or prepares the ground for code execution when combined with file-writing capabilities.

The vulnerabilities have been assigned CVE-2025-68143, CVE-2025-68144 and CVE-2025-68145. Anthropic accepted the reports in September and released fixes in December 2025.

Cyata advised affected users to update immediately and review how MCP servers are combined in their environments, particularly when Git and filesystem access are both enabled.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleChainlit Security Flaws Highlight Infrastructure Risks in AI Apps
Next Article Model Security Is the Wrong Frame – The Real Risk Is Workflow Security
Team-CWD
  • Website

Related Posts

Cyber Security

Interview: Shopify CISO Andrew Dunbar on Securing an E-Commerce Giant

June 26, 2026
Cyber Security

Cisco Vulnerability Exploited Months Before Disclosure, Google Warns

June 25, 2026
Cyber Security

Iran-Linked MuddyWater Poses as Ransomware Gang to Mask Espionage

June 25, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

How it preys on personal data – and how to stay safe

October 23, 2025

What’s at stake if your employees post too much online

December 1, 2025

Why the tech industry needs to stand firm on preserving end-to-end encryption

September 12, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.