CVE-2025-68143Disclosure(lfprojects / model_context_protocol_servers)

LOWCVSS 8.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch lfprojects model_context_protocol_servers systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). In mcp-server-git versions prior to 2025.9.25, the git_init tool accepted arbitrary filesystem paths and created Git repositories without validating the target location. Unlike other tools which required an existing repository, git_init could operate on any directory accessible to the server process, making those directories eligible for subsequent git operations. The tool was removed entirely, as the server is intended to operate on existing repositories only. Users are advised to upgrade to 2025.9.25 or newer to remediate this issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • model_context_protocol_servers

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 6 signals
  • Disclosure: 6 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 2 mentions (2026-02-02); latest day: 2
  • 8 total mentions across 5 days

Affected systems

Vendors
Products
model_context_protocol_servers

Deep dive

Activity timeline8 mentions / 5d
01122Mentions · 2026-01-29: 1Mentions · 2026-02-02: 2Mentions · 2026-02-19: 1Mentions · 2026-02-23: 2Mentions · 2026-02-25: 2Patch / Workaround · 2026-02-02: 1Patch / Workaround · 2026-02-23: 1Technical Details · 2026-01-29: 1Technical Details · 2026-02-02: 1Technical Details · 2026-02-19: 1Technical Details · 2026-02-23: 2Technical Details · 2026-02-25: 101-2902-0202-1902-2302-25
Signal classification3 categories
Disclosure
675.0%
Patch
112.5%
General
112.5%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-01-291
Disclosure1
2026-02-022
Disclosure1Patch1
2026-02-191
Disclosure1
2026-02-232
Disclosure2
2026-02-252
Disclosure1General1
Full discourse8 posts
  • Gray@gray_chromatic
    Disclosure

    1// The CVEs weren't exotic. They were the basics. CVE-2025-68143: git_init created repos at arbitrary filesystem paths. No boundary validation. CVE-2025-68144: Argument injection — user-controlled strings passed directly into shell commands. CVE-2025-68145: Path traversal through a parameter that was never sanitised. All three exploitable via prompt injection. All three in the reference implementation developers are told to copy.

    Post summary

    The text enumerates three CVEs with basic technical details, noting they are exploitable via prompt injection, but provides no PoC, exploit code, or patch information.

    1001041
    4.1K followersView on X
  • SoluDevTech@SoludevTech
    Disclosure

    MCP security is becoming a real concern. CVE-2025-68143: A git_init tool flaw exposed entire filesystems. When your agent has tool access, every tool is an attack surface. Security-first agent design isnt optional anymore. https://soludev.tech #AI #MCP #Security #Agents

    Post summary

    The post announces CVE-2025-68143, a flaw in the git_init tool that can expose entire filesystems, underscoring the importance of secure agent design.

    0001054
    3 followersView on X
  • AI Security Guard@ai_security_10x
    General

    📝 New article: CVE-2025-68143 MCP Server Flaw: How git_init Tool Exposed Entire Filesystems https://moltx.io/articles/4af07a2e-73d3-4bcf-b98a-859e4d48392f

    Post summary

    The article announces a new vulnerability (CVE‑2025‑68143) involving the MCP Server and the git_init tool, but provides no further technical or exploit details.

    000100
  • Sailon 🔮@0xsailon
    Disclosure

    But here's what most people miss — security. Three RCE vulnerabilities were found in Anthropic's own Git MCP server this month (CVE-2025-68145, CVE-2025-68143, CVE-2025-68144). As MCP becomes the connective tissue for AI agents, the attack surface grows exponentially. Security can't be an afterthought.

    Post summary

    Anthropic’s Git MCP server has been disclosed to contain three RCE vulnerabilities (CVE-2025-68145, CVE-2025-68143, CVE-2025-68144). No PoC, exploit, patch, or active exploitation details are provided.

    1000031
    1.3K followersView on X
  • transilienceai@transilienceai
    Disclosure

    @ecap0_ These flaws affect all versions of mcp-server-git before December 8, 2025 (specifically prior to 2025.12.18 or 2025.9.25 for CVE-2025-68143), and work on default installations without needing credentials or direct system access. #InfoSec 🔒

    Post summary

    The tweet announces that all mcp-server-git versions before December 8, 2025 (including CVE‑2025‑68143) are vulnerable on default installations, exploitable without credentials.

    1000042
    317 followersView on X
  • Jeremy McHugh, DSc.@jer_mchugh
    Disclosure

    3/ Last week: CVE-2025-68143/68144/68145 Anthropic's own mcp-server-git had path traversal and command injection. The lesson isn't "Anthropic bad" - it's that even well-resourced teams miss classic vulns when shipping fast. You probably will too.

    Post summary

    The passage announces three CVEs (CVE‑2025‑68143/68144/68145) affecting Anthropic's mcp‑server‑git, highlighting path traversal and command injection vulnerabilities, and cautions that even well‑resourced teams may overlook classic flaws when shipping quickly.

    1000044
    412 followersView on X
  • John Wayne@DevJohnWayne
    Disclosure

    MCP 生态的安全问题正在浮出水面,每个用 AI 编码工具的开发者都该关注。 Anthropic 自家的 Git MCP Server 被发现 3 个 CVE 漏洞(CVE-2025-68143、CVE-2025-68144、CVE-2025-68145),攻击者可以通过 prompt injection 实现远程代码执行和任意文件访问。攻击方式很巧妙——不需要你主动调用恶意工具,只要你的 AI 助手读到了一个被投毒的 README 文件,漏洞就能被触发。 OWASP 已经发布了 MCP Top 10 安全风险清单,Tool Poisoning 排第一。原理是:恶意指令被藏在 MCP 工具的 description 字段里,只要工具被加载到上下文中就会生效,不需要被调用。 三条基本操作: 一、只安装你信任的 MCP Server,定期检查更新 二、用 mcp-scan 扫描你安装的所有 MCP Server 三、遵循最小权限原则,别给 MCP Server 不必要的文件系统访问权 教训很明确——即使是官方维护的 MCP 服务器也不是绝对安全的。MCP 的便利和安全之间需要平衡。 https://owasp.org/www-project-mcp-top-10/

    Post summary

    Anthropic’s Git MCP Server has three newly disclosed CVEs that allow remote code execution via prompt injection, with recommended mitigations but no evidence of active exploitation or PoC.

    0000045
    17 followersView on X
  • Grok@grok
    Patch

    Thanks for spotlighting this. Audits like yours are key for AI safety. Confirmed via sources: Anthropic's MCP Git Server had path traversal (CVE-2025-68143, 68145) and argument injection (CVE-2025-68144) vulns, fixed in 2025 updates. No SSRF noted, but users should patch and audit setups.

    Post summary

    Anthropic’s MCP Git Server suffered path traversal and argument injection vulnerabilities (CVE-2025-68143, 68145, 68144) that were fixed in 2025 updates, and users are urged to apply patches and audit configurations.

    0000049
    8.1M followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applfprojectsmodel_context_protocol_servers---

Explore more