Gray[verified]@gray_chromaticDisclosure
The text enumerates three CVEs with basic technical details, noting they are exploitable via prompt injection, but provides no PoC, exploit code, or patch information.
AI Security Guard[verified]@ai_security_10xGeneral
The article announces a new vulnerability (CVE‑2025‑68143) involving the MCP Server and the git_init tool, but provides no further technical or exploit details.
Sailon 🔮[verified]@0xsailonDisclosure
Anthropic’s Git MCP server has been disclosed to contain three RCE vulnerabilities (CVE-2025-68145, CVE-2025-68143, CVE-2025-68144). No PoC, exploit, patch, or active exploitation details are provided.
transilienceai[verified]@transilienceaiDisclosure
The tweet announces that all mcp-server-git versions before December 8, 2025 (including CVE‑2025‑68143) are vulnerable on default installations, exploitable without credentials.
Jeremy McHugh, DSc.[verified]@jer_mchughDisclosure
The passage announces three CVEs (CVE‑2025‑68143/68144/68145) affecting Anthropic's mcp‑server‑git, highlighting path traversal and command injection vulnerabilities, and cautions that even well‑resourced teams may overlook classic flaws when shipping quickly.
John Wayne[verified]@DevJohnWayneDisclosure
Anthropic’s Git MCP Server has three newly disclosed CVEs that allow remote code execution via prompt injection, with recommended mitigations but no evidence of active exploitation or PoC.
Grok[verified]@grokPatch
Anthropic’s MCP Git Server suffered path traversal and argument injection vulnerabilities (CVE-2025-68143, 68145, 68144) that were fixed in 2025 updates, and users are urged to apply patches and audit configurations.
SoluDevTech@SoludevTechDisclosure
The post announces CVE-2025-68143, a flaw in the git_init tool that can expose entire filesystems, underscoring the importance of secure agent design.