Anthropic’s official Git MCP server had some troubling security flaws – this is what happened next


  • Anthropic patched Git MCP bugs enabling remote code execution via toolchain
  • Cyata detected CVEs; fixed in version 2025.12.18, no exploit reported yet
  • Claude has previously manipulated in a cyberespionage campaign targeting large global organizations

Anthropic, the company behind the popular AI model Claude, has fixed several bugs in its Git MCP server, which researchers say can be chained with other MCP tools to enable remote code execution (RCE) or file manipulation through rapid injection.

The Git MCP server is Anthropic’s Model Context Protocol service that lets AI tools read and interact with Git repositories. This is important because it allows the AI ​​to understand real codebases or answer coding questions without insecure or unrestricted access.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top