Anthropic’s official Git MCP server had worrying security vulnerabilities – here’s what happened next


  • Anthropic fixed Git MCP vulnerabilities allowing remote code execution via tool chaining
  • Cyata discovered the CVEs; fixed in version 2025.12.18, no exploitation reported yet
  • Claude was previously manipulated as part of a cyberespionage campaign targeting major global organizations

Anthropic, the company behind the popular AI model Claude, has fixed several bugs in its MCP Git server which researchers say can be chained with other MCP tools to enable remote code execution (RCE) or file tampering via rapid injection.

The MCP Git Server is Anthropic’s Model Context Protocol service that allows AI tools to read and interact with Git repositories. This is important because it allows AI to understand real code bases or answer coding questions without dangerous or unrestricted access.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top