A set of three security vulnerabilities have been disclosed in mcp-server-git, the official Git Model Context Protocol (MCP) maintained by Anthropic, which could be exploited to read or delete arbitrary files and execute code under certain circumstances.
See also: Anthropic launches Claude AI for Healthcare

“ These vulnerabilities can be exploited via command injection, meaning an attacker who can influence what an AI assistant reads (a malicious README, a poisoned issue description, a compromised web page) can exploit these vulnerabilities without direct access to the victim’s system ,” Cyata researcher Yarden Porat said in a report shared with The Hacker News.
mcp-server-git is a Python package and MCP server that provides a set of built-in tools for reading, searching, and manipulating Git repositories programmatically via large language models (LLMs). The security issues, which have been addressed in versions 2025.9.25 and 2025.12.18 after responsible disclosure in June 2025, are listed below:
- CVE-2025-68143 (CVSS: 8.8 [v3] / 6.5 [v4]) Path traversal vulnerability that occurs because the git_init tool allows the use of arbitrary filesystem paths when creating repositories, without sufficient validation. Fixed in version 2025.9.25.
- CVE-2025-68144 (CVSS: 8.1 [v3] / 6.4 [v4]) Argument injection vulnerability due to the git_diff and git_checkout functions directly passing user-controlled arguments to Git CLI commands, without proper sanitization. Fixed in version 2025.12.18.
- CVE-2025-68145 (CVSS: 7.1 [v3] / 6.3 [v4]) Path traversal vulnerability due to the lack of path checking when using the –repository parameter , which is intended to restrict operations to a specific repository. Fixed in version 2025.12.18.
See also: OpenAI ChatGPT and Anthropic take measures for underage users

Successful exploitation of the above vulnerabilities could allow an attacker to convert any directory on the system into a Git repository, replace any file with an empty diff, and gain access to any repository on the server.
In an attack scenario documented by Cyata, the three vulnerabilities could be combined with the MCP Filesystem to write to a “.git/config” file and achieve remote code execution by invoking a call to git_init via command injection. In response to the findings, the git_init tool has been removed from the package and additional checks are being added to prevent path prototypes.
See also: Anthropic brings Claude Code to Slack

Users of the Python package are advised to update to the latest version for optimal protection. “This is the standard MCP Git server, which developers are expected to copy,” said Shahar Tal, CEO and co-founder of security firm Agentic AI Cyata. “If security boundaries are broken even in the implementation report, it’s a signal that the entire MCP ecosystem needs a deeper look. These are not edge cases or exotic configurations, they work out of the box.”
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
