Gray[verified]@gray_chromaticDisclosure
The post discloses three CVEs with basic technical details, noting they can be exploited via prompt injection, but provides no PoC, exploit code, patch, or evidence of active exploitation.
transilienceai[verified]@transilienceaiDisclosure
The tweet announces CVE-2025-68145, a path‑traversal flaw with CVSS 7.1 due to missing validation on the `--repository` flag, with no PoC, exploit, patch or active exploitation reported.
AgentVet[verified]@AgentVet_ioGeneral
The post lists two CVEs that may affect MCP connectors and warns about third‑party supply chain exposure, but it does not provide a PoC, exploit, patch, or evidence of wild exploitation.
Sailon 🔮[verified]@0xsailonDisclosure
The post announces the discovery of three RCE vulnerabilities (CVE-2025-68145, CVE-2025-68143, CVE-2025-68144) in Anthropic’s Git MCP server, highlighting the expanding attack surface as AI agents become more connected.
transilienceai[verified]@transilienceaiPatch
The tweet describes a path traversal flaw in CVE‑2025‑68145 that enables access to any repository, and notes that the issue has been fixed by enforcing path validation.
transilienceai[verified]@transilienceaiDisclosure
CVE‑2025‑68145 is disclosed as an improper validation of repo_path arguments that lets users bypass repository restrictions and access any repository on the server.
John Wayne[verified]@DevJohnWayneDisclosure
Anthropic’s Git MCP Server has three newly disclosed CVEs (CVE‑2025‑68143, ‑68144, ‑68145) that enable remote code execution via prompt injection, with mitigation advice to trust servers, scan, and limit filesystem access.
AIUNRegistry@AIUNRegistryDisclosure
The text reports a path traversal flaw (CVE-2025-68145) discovered in Anthropic’s official Git MCP server, noting that the vulnerability allows reading arbitrary files outside the repo.