GitPython is a tool tracked across 1 threat cluster and 2 intelligence report mentions on ThreatCluster. First observed January 20, 2026; most recent activity January 20, 2026.
The articles describe flaws in Anthropic's Git MCP server, a Git-based management/control plane used within Anthropic's infrastructure. The vulnerabilities enabled remote code execution, creating a high-severity risk for potential adversaries seeking to compromise the server or pivot within the environment. Anthropic quietly patched the issues on 2026-01-20, highlighting the importance of securing Git-based tooling and internal CI-like components.
Anthropic has addressed three vulnerabilities in its Git MCP server, which could be exploited to remotely execute malicious code or overwrite files through prompt injection. The server connects various AI tools to Git…