Three zero-day vulnerabilities in mcp-server-git, the reference implementation of Git integration for the Model Context Protocol (MCP). The flaws stem from insufficient input validation and argument sanitization in core Git operations. Through prompt injection, attackers can execute code, delete files, and exfiltrate sensitive data without direct system access. Patches are available in version 2025.12.18 and […]
The post Multiple 0-day Vulnerabilities in Anthropic Git MCP Server Enables Code Execution appeared first on Cyber Security News.
Read the original article: