CVE-2025-68143

Published Dec 17, 2025

Last updated 4 months ago

CVSS medium 6.5
Open source

Overview

Description
Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). In mcp-server-git versions prior to 2025.9.25, the git_init tool accepted arbitrary filesystem paths and created Git repositories without validating the target location. Unlike other tools which required an existing repository, git_init could operate on any directory accessible to the server process, making those directories eligible for subsequent git operations. The tool was removed entirely, as the server is intended to operate on existing repositories only. Users are advised to upgrade to 2025.9.25 or newer to remediate this issue.
Source
security-advisories@github.com
NVD status
Analyzed
Products
model_context_protocol_servers

Risk scores

CVSS 4.0

Type
Secondary
Base score
6.5
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
MEDIUM

CVSS 3.1

Type
Primary
Base score
8.8
Impact score
5.9
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

security-advisories@github.com
CWE-22

Social media

Hype score
Not currently trending
  1. MCP security is becoming a real concern. CVE-2025-68143: A git_init tool flaw exposed entire filesystems. When your agent has tool access, every tool is an attack surface. Security-first agent design isnt optional anymore. https://t.co/zbfFXif2JM #AI #MCP #Security #Agents

    @SoludevTech

    25 Feb 2026

    49 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 📝 New article: CVE-2025-68143 MCP Server Flaw: How git_init Tool Exposed Entire Filesystems https://t.co/JHbecPwqIw

    @ai_security_10x

    25 Feb 2026

    0 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  3. MCP 生态的安全问题正在浮出水面,每个用 AI 编码工具的开发者都该关注。 Anthropic 自家的 Git MCP Server 被发现 3 个 CVE 漏洞(CVE-2025-68143、CVE-2025-68144、CVE-2025-68145),攻击者可以通过 prompt injection

    @DevJohnWayne

    23 Feb 2026

    39 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 🚨 Anthropic Patches Critical Flaws in Git MCP Server Enabling File Access and Potential RCE Security researchers disclosed three high-severity issues in Anthropic’s mcp-server-git (CVE-2025-68143/68144/68145) that can be chained with the Filesystem MCP server to bypass path

    @ThreatSynop

    21 Jan 2026

    35 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. Anthropic의 공식 MCP Git 서버에서 임의 파일 접근 및 코드 실행을 가능하게 하는 3가지 보안 취약점(CVE-2025-68143, CVE-2025-68144, CVE-2025-68145)이 발견되었습니다. 프롬프트 인젝션을 통한 공격 가능성이 확인되었습니다. h

    @webi_kr

    21 Jan 2026

    34 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. 🚨 Anthropic Git MCP Server Flaws Enable Prompt-Injection RCE and File Access (“Chain of Tool Abuse”) Cyata found three vulnerabilities in Anthropic’s official Git MCP server (CVE-2025-68143/68144/68145) where attacker-controlled arguments via prompt injection (e.g., mali

    @ThreatSynop

    21 Jan 2026

    41 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. Researchers at Cyata have identified three critical vulnerabilities in Anthropic’s official Git Model Context Protocol (MCP) server that could allow attackers to manipulate large language models (LLMs) through prompt injection attacks. These flaws, tracked as CVE-2025-68143,

    @ox0ffff

    21 Jan 2026

    57 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. 🚨 Anthropic MCP Git Server Flaws Let Prompt Injection Read/Delete Files and Trigger Code Execution Three vulnerabilities in Anthropic’s official mcp-server-git (CVE-2025-68143/68144/68145) enable path traversal and argument injection that attackers can weaponize via

    @ThreatSynop

    20 Jan 2026

    47 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. CVE-2025-68143 Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). In mcp-server-git versions prior to 2025.9.25, the g… https://t.co/xC36LAxbuG

    @CVEnew

    20 Dec 2025

    151 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. 🟠 mcp-server-git, Path Traversal, #CVE-2025-68143 (Moderate) https://t.co/HXejoIycL1

    @dailycve

    17 Dec 2025

    8 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations