PANews reported on January 21 that, according to The Hacker News, Cyata researchers disclosed three serious security vulnerabilities (CVE-2025-68143/44/45) in the mcp-server-git server maintained by Anthropic. These vulnerabilities can be exploited to traverse execution paths and inject parameters, potentially even enabling remote code execution. These vulnerabilities can be weaponized through prompt injection, allowing attackers to trigger attacks simply by controlling an AI assistant to read malicious content. The vulnerabilities have been patched in the September and December 2025 versions. The official git_init tool has been removed, and path verification has been strengthened. Users are advised to update to the latest version as soon as possible.


