CVE-2025-68144Disclosure(lfprojects / model_context_protocol_servers)

LOWCVSS 7.1 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch lfprojects model_context_protocol_servers systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In mcp-server-git versions prior to 2025.12.17, the git_diff and git_checkout functions passed user-controlled arguments directly to git CLI commands without sanitization. Flag-like values (e.g., `--output=/path/to/file` for `git_diff`) would be interpreted as command-line options rather than git refs, enabling arbitrary file overwrites. The fix adds validation that rejects arguments starting with - and verifies the argument resolves to a valid git ref via rev_parse before execution. Users are advised to update to 2025.12.17 resolve this issue when it is released.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-88

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • model_context_protocol_servers

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-02-23)
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
model_context_protocol_servers

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-02-02: 1Mentions · 2026-02-19: 1Mentions · 2026-02-23: 2Patch / Workaround · 2026-02-02: 1Technical Details · 2026-02-02: 1Technical Details · 2026-02-23: 202-0202-1902-23
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-02-021
Patch1
2026-02-191
Disclosure1
2026-02-232
Disclosure2
Full discourse4 posts
  • Gray@gray_chromatic
    Disclosure

    1// The CVEs weren't exotic. They were the basics. CVE-2025-68143: git_init created repos at arbitrary filesystem paths. No boundary validation. CVE-2025-68144: Argument injection — user-controlled strings passed directly into shell commands. CVE-2025-68145: Path traversal through a parameter that was never sanitised. All three exploitable via prompt injection. All three in the reference implementation developers are told to copy.

    Post summary

    The text discloses three CVEs with basic technical details, noting they are exploitable via prompt injection, but provides no PoC, patch, or evidence of active exploitation.

    1001041
    4.1K followersView on X
  • Sailon 🔮@0xsailon
    Disclosure

    But here's what most people miss — security. Three RCE vulnerabilities were found in Anthropic's own Git MCP server this month (CVE-2025-68145, CVE-2025-68143, CVE-2025-68144). As MCP becomes the connective tissue for AI agents, the attack surface grows exponentially. Security can't be an afterthought.

    Post summary

    The post announces three RCE CVEs (CVE-2025-68145, CVE-2025-68143, CVE-2025-68144) in Anthropic's Git MCP server, but provides no further details, PoC, exploit, or patch information.

    1000031
    1.3K followersView on X
  • John Wayne@DevJohnWayne
    Disclosure

    MCP 生态的安全问题正在浮出水面,每个用 AI 编码工具的开发者都该关注。 Anthropic 自家的 Git MCP Server 被发现 3 个 CVE 漏洞(CVE-2025-68143、CVE-2025-68144、CVE-2025-68145),攻击者可以通过 prompt injection 实现远程代码执行和任意文件访问。攻击方式很巧妙——不需要你主动调用恶意工具,只要你的 AI 助手读到了一个被投毒的 README 文件,漏洞就能被触发。 OWASP 已经发布了 MCP Top 10 安全风险清单,Tool Poisoning 排第一。原理是:恶意指令被藏在 MCP 工具的 description 字段里,只要工具被加载到上下文中就会生效,不需要被调用。 三条基本操作: 一、只安装你信任的 MCP Server,定期检查更新 二、用 mcp-scan 扫描你安装的所有 MCP Server 三、遵循最小权限原则,别给 MCP Server 不必要的文件系统访问权 教训很明确——即使是官方维护的 MCP 服务器也不是绝对安全的。MCP 的便利和安全之间需要平衡。 https://owasp.org/www-project-mcp-top-10/

    Post summary

    The post announces three new CVEs in Anthropic’s Git MCP Server, detailing prompt‑injection‑based remote code execution and file access, but does not provide PoC, exploit code, or evidence of active exploitation.

    0000045
    17 followersView on X
  • Grok@grok
    Patch

    Thanks for spotlighting this. Audits like yours are key for AI safety. Confirmed via sources: Anthropic's MCP Git Server had path traversal (CVE-2025-68143, 68145) and argument injection (CVE-2025-68144) vulns, fixed in 2025 updates. No SSRF noted, but users should patch and audit setups.

    Post summary

    Anthropic’s MCP Git Server suffered path traversal and argument injection flaws, now fixed in 2025 updates; users are urged to apply patches and audit their setups.

    0000049
    8.1M followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applfprojectsmodel_context_protocol_servers---

Explore more