{
 "license": "CC-BY-4.0",
 "attribution": "Fide AI, Agentic Cyber Explorer",
 "url": "https://agentic-cyber-explorer.pages.dev/events/cyata-anthropic-git-mcp-server-cves-2026/",
 "asOf": "2026-09-26",
 "id": "cyata-anthropic-git-mcp-server-cves-2026",
 "date": "2026-01-20",
 "datePrecision": "day",
 "title": "Cyata discloses three flaws in Anthropic's reference Git MCP server reachable via prompt injection",
 "lane": "attack",
 "kind": "vulnerability-disclosure",
 "summary": "Cyata found path-validation and argument-injection flaws in Anthropic's mcp-server-git (CVE-2025-68143, -68144, -68145) that, chained with the Filesystem MCP server, allowed file access and code execution by anyone able to influence what the assistant reads. Anthropic removed the git_init tool and added path validation in fixed releases.",
 "whyItMatters": "Even the protocol author's reference servers carried injection-reachable code execution paths.",
 "actors": [
  "cyata",
  "anthropic"
 ],
 "topics": [
  "tool-and-mcp-security",
  "prompt-injection"
 ],
 "atlas": [
  "tools",
  "untrusted-content",
  "sandbox"
 ],
 "artifacts": [],
 "sources": [
  {
   "url": "https://cyata.ai/blog/cyata-research-breaking-anthropics-official-mcp-server/",
   "publisher": "Cyata",
   "title": "Cyata Research: Breaking Anthropic’s Official MCP Server",
   "date": "2026-01-20",
   "type": "primary",
   "accessed": "2026-09-26"
  },
  {
   "url": "https://github.com/modelcontextprotocol/servers/security/advisories/GHSA-5cgr-j3jf-jw3v",
   "publisher": "Model Context Protocol servers (GitHub security advisory)",
   "title": "GHSA-5cgr-j3jf-jw3v",
   "date": "2025-12-17",
   "type": "primary",
   "accessed": "2026-09-26"
  },
  {
   "url": "https://github.com/modelcontextprotocol/servers/security/advisories/GHSA-9xwc-hfwc-8w59",
   "publisher": "Model Context Protocol servers (GitHub security advisory)",
   "title": "GHSA-9xwc-hfwc-8w59",
   "date": "2025-12-17",
   "type": "primary",
   "accessed": "2026-09-26"
  },
  {
   "url": "https://github.com/modelcontextprotocol/servers/security/advisories/GHSA-j22h-9j4x-23w5",
   "publisher": "Model Context Protocol servers (GitHub security advisory)",
   "title": "GHSA-j22h-9j4x-23w5",
   "date": "2025-12-17",
   "type": "primary",
   "accessed": "2026-09-26"
  },
  {
   "url": "https://thehackernews.com/2026/01/three-flaws-in-anthropic-mcp-git-server.html",
   "publisher": "The Hacker News",
   "title": "Three Flaws in Anthropic MCP Git Server Enable File Access and Code Execution",
   "date": "2026-01-20",
   "type": "secondary",
   "accessed": "2026-09-25"
  }
 ],
 "keyFacts": [
  {
   "fact": "CVE-2025-68143 fixed in mcp-server-git version 2025.9.25; CVE-2025-68144 and CVE-2025-68145 fixed in version 2025.12.18, per The Hacker News.",
   "locator": "The Hacker News, CVE list"
  }
 ],
 "significance": 3,
 "fideQuestions": [],
 "methods": [
  "indirect-prompt-injection",
  "tool-poisoning"
 ],
 "review": "assistant-drafted",
 "addedOn": "2026-09-25"
}