
Three Security Vulnerabilities Disclosed in Anthropic's MCP Git Server
cybersecurityvulnerabilitiesgit_serverAnthropicMCPprompt_injectionremote_code_executiondata_breachfile_deletionzero_day
Three security vulnerabilities have been disclosed in mcp-server-git, the official Git server for the Model Context Protocol (MCP) maintained by Anthropic. These flaws allow an attacker to access, delete arbitrary files, or execute code under certain conditions. They can be exploited through prompt injection attacks, particularly by manipulating files such as a malicious README. The impacts include unauthorized data access, file deletion, and remote code execution. No specific disclosure date or additional technical details (such as CVE references) are mentioned.