
- Anthropic patched Git MCP flaws enabling remote code execution via tool chaining
- Cyata discovered CVEs; fixed in version 2025.12.18, no exploitation reported yet
- Claude previously manipulated in cyber espionage campaign targeting major global organizations
Anthropic, the company behind the popular AI model Claude has fixed multiple bugs in its Git MCP server which, researchers claim, can be chained with other MCP tools to enable remote code execution (RCE) or file tampering through prompt injection.