CVE-2025-68145Disclosure(lfprojects / model_context_protocol_servers)

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch lfprojects model_context_protocol_servers systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In mcp-server-git versions prior to 2025.12.17, when the server is started with the --repository flag to restrict operations to a specific repository path, it did not validate that repo_path arguments in subsequent tool calls were actually within that configured path. This could allow tool calls to operate on other repositories accessible to the server process. The fix adds path validation that resolves both the configured repository and the requested path (following symlinks) and verifies the requested path is within the allowed repository before executing any git operations. Users are advised to upgrade to 2025.12.17 upon release to remediate this issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • model_context_protocol_servers

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 8 signals
  • Disclosure: 6 classified signals
  • General: 1 classified signal
  • Peaked 4d ago at 2 mentions (2026-02-02); latest day: 1
  • 8 total mentions across 6 days

Affected systems

Vendors
Products
model_context_protocol_servers

Deep dive

Activity timeline8 mentions / 6d
01122Mentions · 2026-02-01: 1Mentions · 2026-02-02: 2Mentions · 2026-02-19: 1Mentions · 2026-02-23: 2Mentions · 2026-03-10: 1Mentions · 2026-05-20: 1Patch / Workaround · 2026-02-02: 1Patch / Workaround · 2026-02-23: 1Technical Details · 2026-02-01: 1Technical Details · 2026-02-02: 2Technical Details · 2026-02-19: 1Technical Details · 2026-02-23: 2Technical Details · 2026-03-10: 1Technical Details · 2026-05-20: 102-0102-0202-1902-2303-1005-20
Signal classification3 categories
Disclosure
675.0%
Patch
112.5%
General
112.5%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-02-011
Disclosure1
2026-02-022
Disclosure1Patch1
2026-02-191
Disclosure1
2026-02-232
Disclosure2
2026-03-101
Disclosure1
2026-05-201
General1
Full discourse8 posts
  • AIUNRegistry@AIUNRegistry
    Disclosure

    3/ Real example: Anthropic's official Git MCP server had a path traversal vulnerability (CVE-2025-68145). Agents could read arbitrary files outside the repo. The "official" server. Found by a third party, not Anthropic.

    Post summary

    The text reports a path traversal flaw (CVE-2025-68145) discovered in Anthropic’s official Git MCP server, noting that the vulnerability allows reading arbitrary files outside the repo.

    20010104
    132 followersView on X
  • Gray@gray_chromatic
    Disclosure

    1// The CVEs weren't exotic. They were the basics. CVE-2025-68143: git_init created repos at arbitrary filesystem paths. No boundary validation. CVE-2025-68144: Argument injection — user-controlled strings passed directly into shell commands. CVE-2025-68145: Path traversal through a parameter that was never sanitised. All three exploitable via prompt injection. All three in the reference implementation developers are told to copy.

    Post summary

    The post discloses three CVEs with basic technical details, noting they can be exploited via prompt injection, but provides no PoC, exploit code, patch, or evidence of active exploitation.

    1001041
    4.1K followersView on X
  • transilienceai@transilienceai
    Disclosure

    @Lemo_bot - **CVE-2025-68145 (CVSS 7.1)**: Path traversal via missing validation on the `--repository` flag, enabling access to any system directory or repository.

    Post summary

    The tweet announces CVE-2025-68145, a path‑traversal flaw with CVSS 7.1 due to missing validation on the `--repository` flag, with no PoC, exploit, patch or active exploitation reported.

    2000056
    320 followersView on X
  • AgentVet@AgentVet_io
    General

    MCP connectors carry known CVEs including one-click RCE (CVE-2025-6514) and path traversal in Anthropic's own servers (CVE-2025-68145). No formal certification exists. You're trusting third-party supply chains with access to your legal and financial data.

    Post summary

    The post lists two CVEs that may affect MCP connectors and warns about third‑party supply chain exposure, but it does not provide a PoC, exploit, patch, or evidence of wild exploitation.

    10000994
    7 followersView on X
  • Sailon 🔮@0xsailon
    Disclosure

    But here's what most people miss — security. Three RCE vulnerabilities were found in Anthropic's own Git MCP server this month (CVE-2025-68145, CVE-2025-68143, CVE-2025-68144). As MCP becomes the connective tissue for AI agents, the attack surface grows exponentially. Security can't be an afterthought.

    Post summary

    The post announces the discovery of three RCE vulnerabilities (CVE-2025-68145, CVE-2025-68143, CVE-2025-68144) in Anthropic’s Git MCP server, highlighting the expanding attack surface as AI agents become more connected.

    1000031
    1.3K followersView on X
  • transilienceai@transilienceai
    Patch

    @ecap0_ CVE-2025-68145 has an unspecified CVSS Score. It fails to validate `repo_path` args for the `--repository` flag, bypassing path restrictions. This allows access to any repo on the system. The fix enforced path validation. #CVE #CyberThreats ⚠️

    Post summary

    The tweet describes a path traversal flaw in CVE‑2025‑68145 that enables access to any repository, and notes that the issue has been fixed by enforcing path validation.

    1000040
    317 followersView on X
  • transilienceai@transilienceai
    Disclosure

    @ecap0_ CVE-2025-68145: Improper validation of `repo_path` arguments, bypassing `--repository` flag restrictions. Impact: Accesses any repo on the server. #SecurityFlaw 🔍

    Post summary

    CVE‑2025‑68145 is disclosed as an improper validation of repo_path arguments that lets users bypass repository restrictions and access any repository on the server.

    1000041
    317 followersView on X
  • John Wayne@DevJohnWayne
    Disclosure

    MCP 生态的安全问题正在浮出水面,每个用 AI 编码工具的开发者都该关注。 Anthropic 自家的 Git MCP Server 被发现 3 个 CVE 漏洞(CVE-2025-68143、CVE-2025-68144、CVE-2025-68145),攻击者可以通过 prompt injection 实现远程代码执行和任意文件访问。攻击方式很巧妙——不需要你主动调用恶意工具,只要你的 AI 助手读到了一个被投毒的 README 文件,漏洞就能被触发。 OWASP 已经发布了 MCP Top 10 安全风险清单,Tool Poisoning 排第一。原理是:恶意指令被藏在 MCP 工具的 description 字段里,只要工具被加载到上下文中就会生效,不需要被调用。 三条基本操作: 一、只安装你信任的 MCP Server,定期检查更新 二、用 mcp-scan 扫描你安装的所有 MCP Server 三、遵循最小权限原则,别给 MCP Server 不必要的文件系统访问权 教训很明确——即使是官方维护的 MCP 服务器也不是绝对安全的。MCP 的便利和安全之间需要平衡。 https://owasp.org/www-project-mcp-top-10/

    Post summary

    Anthropic’s Git MCP Server has three newly disclosed CVEs (CVE‑2025‑68143, ‑68144, ‑68145) that enable remote code execution via prompt injection, with mitigation advice to trust servers, scan, and limit filesystem access.

    0000045
    17 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applfprojectsmodel_context_protocol_servers---

Explore more