Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Anthropic MCP Server Flaws Lead to Code Execution, Data Exposure

Anthropic MCP Server Flaws Lead to Code Execution, Data Exposure

Posted on January 21, 2026January 21, 2026 By CWS

New analysis from Cyata reveals that flaws within the servers connecting LLMs to native knowledge through Anthropic’s MCP may be exploited to attain distant code execution and unauthorized file entry.

All three flaws had been recognized within the official Git MCP server (mcp-server-git) maintained by Anthropic and may very well be exploited through immediate injections with attacker-controlled arguments.

“MCP servers execute actions primarily based on LLM selections, and LLMs may be manipulated via immediate injection,” Cyata defined. “A malicious actor who can affect the AI’s context can set off MCP software calls with attacker-controlled arguments.”

The bugs, tracked as CVE-2025-68143, CVE-2025-68145, and CVE-2025-68144, existed as a result of the Git MCP server did not validate or sanitize particular arguments offered by an attacker.

“These flaws may be exploited via immediate injection, which means an attacker who can affect what an AI assistant reads (a malicious README, a poisoned problem description, a compromised webpage) can weaponize these vulnerabilities with none direct entry to the sufferer’s system,” Cyata stated.

The safety agency’s researchers confirmed how an attacker may exploit the vulnerabilities for arbitrary code execution, studying recordsdata, and deleting recordsdata, with the assault working in opposition to any configuration. Commercial. Scroll to proceed studying.

The cybersecurity agency first reported the problems to Anthropic in June and July 2025.

The seller resolved all three vulnerabilities in December, in mcp-server-git model 2025.12.18.

Associated: Chainlit Vulnerabilities Might Leak Delicate Data

Associated: Weaponized Invite Enabled Calendar Knowledge Theft through Google Gemini

Associated: LLMs in Attacker Crosshairs, Warns Menace Intel Agency

Associated: WormGPT 4 and KawaiiGPT: New Darkish LLMs Increase Cybercrime Automation

Security Week News Tags:Anthropic, Code, Data, Execution, Exposure, Flaws, Lead, MCP, Server

Post navigation

Previous Post: Oracle’s First 2026 CPU Delivers 337 New Security Patches
Next Post: How Smart MSSPs Using AI to Boost Margins with Half the Staff

Related Posts

Cambodia Makes 1,000 Arrests in Latest Crackdown on Cybercrime Cambodia Makes 1,000 Arrests in Latest Crackdown on Cybercrime Security Week News
Origin Energy Confirms Data Breach Impacting Millions Origin Energy Confirms Data Breach Impacting Millions Security Week News
DataBahn Secures M to Enhance Data Management Solutions DataBahn Secures $40M to Enhance Data Management Solutions Security Week News
RSAC 2026: Key Highlights from Days 3-4 RSAC 2026: Key Highlights from Days 3-4 Security Week News
Cyber Insights 2026: Malware and Cyberattacks in the Age of AI Cyber Insights 2026: Malware and Cyberattacks in the Age of AI Security Week News
Company and Personal Data Compromised in Recent Insight Partners Hack  Company and Personal Data Compromised in Recent Insight Partners Hack  Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Local AI Model Evades EDR Detection with Modified Credential Dumper
  • Enhancing AI Agent Security with Zero Trust Principles
  • Critical Vulnerability in Oracle PeopleSoft Exploited Globally
  • Kiteworks Recommends Nine-Hour System Shutdown Amid Cyber Threat
  • New Botnet x47.c Leverages AI for Advanced Cyber Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Local AI Model Evades EDR Detection with Modified Credential Dumper
  • Enhancing AI Agent Security with Zero Trust Principles
  • Critical Vulnerability in Oracle PeopleSoft Exploited Globally
  • Kiteworks Recommends Nine-Hour System Shutdown Amid Cyber Threat
  • New Botnet x47.c Leverages AI for Advanced Cyber Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark