PANews reported on January 21 that, according to The Hacker News, Cyata researchers disclosed three serious security vulnerabilities (CVE-2025-68143/44/45) in thePANews reported on January 21 that, according to The Hacker News, Cyata researchers disclosed three serious security vulnerabilities (CVE-2025-68143/44/45) in the

Anthropic fixes three high-risk vulnerabilities in the MCP Git server, involving arbitrary file access and remote code execution.

2026/01/21 09:52

PANews reported on January 21 that, according to The Hacker News, Cyata researchers disclosed three serious security vulnerabilities (CVE-2025-68143/44/45) in the mcp-server-git server maintained by Anthropic. These vulnerabilities can be exploited to traverse execution paths and inject parameters, potentially even enabling remote code execution. These vulnerabilities can be weaponized through prompt injection, allowing attackers to trigger attacks simply by controlling an AI assistant to read malicious content. The vulnerabilities have been patched in the September and December 2025 versions. The official git_init tool has been removed, and path verification has been strengthened. Users are advised to update to the latest version as soon as possible.

Market Opportunity
Prompt Logo
Prompt Price(PROMPT)
$0.05663
$0.05663$0.05663
-0.03%
USD
Prompt (PROMPT) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.