TODAYINFO
  • finance
  • technology
  • military
  • world
  1. TODAYINFO
  2. technology

GitHub MCP vulnerability exposed: Attackers can access private repositories using malicious issues

2025-06-02 00:13:14 HKTtodayinfo

IT Home June 1st news, GitHub's official MCP server can give large language models a number of new capabilities, including reading repository issues that users have access to and submitting new pull requests (PRs). This constitutes a triple threat to prompt injection attacks: private data access, malicious instructions exposure, and information leakage capabilities.

Swiss cybersecurity company Invariant Labs posted on Thursday that they found a vulnerability in GitHub’s official MCP server, and attackers could hide malicious instructions in public repositories, inducing AI agents such as Claude 4 to leak sensitive data from MCP users’ private repositories. At the same time, similar vulnerabilities also appear in GitLab Duo.

The core of the attack is to obtain "other repositories that the user is processing" information. Since the MCP server has access to the user's private repository, LLM will create a new PR after processing the issue - which exposes the private repository name.

In the Invariant test case, the user only needs to issue the following request to Claude to trigger information leakage:

▲ User command

▲ Complete chat screenshot

It is worth mentioning that if multiple MCP servers are combined (one accesses private data, the other exposes malicious intentions Token, the third leaked data will pose a greater risk. GitHub MCP has now integrated these three elements into a single system.

Detailed explanation of the attack mechanism

Preconditions:

Users use Claude, etc. MCP client and bind GitHub account

The user has both a public repository (such as /public-repo) and a private repository (such as /private-repo)

Attack process:

The attacker creates a malicious issue with prompt injection in a public repository

The user sends a regular request to Claude (such as "View the issue of pacman open source repository")

AI triggers a malicious instruction when obtaining a public repository

AI pulls private repository data into the context

AI creates a PR with private data in a public repository (IT Home Note: The attacker can access the data publicly)

Performance results:

Successfully leaks out of the user ukend0464 Private warehouse information

Leaked content includes sensitive data such as private project "Jupiter Star", immigration plan, salary, etc.

This vulnerability originates from AI workflow design flaws, not traditional GitHub platform vulnerabilities. In response, the company proposed two sets of defense solutions: dynamic permission control, restricting access rights of AI agents; continuous security monitoring, intercepting abnormal data flow through real-time behavioral analysis and context-aware policies.

Latest articles
  • You can take the college entrance examination with peace of mind, and we will protect you! You can take the college entrance examination with peace of mind, and we will protect you! military | 2025-06-07
  • Macron, who realized that he had made a mistake, changed his attitude! China prepares a great gift, can it get the opinion of morality and sincerity Macron, who realized that he had made a mistake, changed his attitude! China prepares a great gift, can it get the opinion of morality and sincerity world | 2025-06-07
  • The commander-in-chief of the Thai Army signed the order! Authorize border troops to fully control the Thai-Cambodia border gate! The commander-in-chief of the Thai Army signed the order! Authorize border troops to fully control the Thai-Cambodia border gate! world | 2025-06-07
  • The Guatemala president visits Taiwan and meets Lai Ching-te. The Ministry of Foreign Affairs responds domineeringly The Guatemala president visits Taiwan and meets Lai Ching-te. The Ministry of Foreign Affairs responds domineeringly military | 2025-06-07
  • revenge! Russia launched an attack in the early morning, "unprecedented in scale" revenge! Russia launched an attack in the early morning, "unprecedented in scale" military | 2025-06-07
  • Pressure escalates! Trump: Powell's successor is "coming soon" Pressure escalates! Trump: Powell's successor is "coming soon" world | 2025-06-07
  • China and the United States finalize the second round of negotiations, and rare earths become Trump's heart disease, and China has the power to dominate the whole process China and the United States finalize the second round of negotiations, and rare earths become Trump's heart disease, and China has the power to dominate the whole process finance | 2025-06-07
  • Wu said that he shot down a Russian-Sui-35 fighter jet, and the scene was exposed Wu said that he shot down a Russian-Sui-35 fighter jet, and the scene was exposed military | 2025-06-07
  • Official notification from Zhanjiang public officials laughed and retorted to the host: Two people involved were suspended for inspection Official notification from Zhanjiang public officials laughed and retorted to the host: Two people involved were suspended for inspection finance | 2025-06-07
  • News: Wu said it shot down a Russian-Sui-35 fighter jet News: Wu said it shot down a Russian-Sui-35 fighter jet military | 2025-06-07
  • Street chaos! Los Angeles mayor angrily arrests illegal immigrants on a large scale Street chaos! Los Angeles mayor angrily arrests illegal immigrants on a large scale world | 2025-06-07
  • The South Korea-US alliance is preferred, Lee Zai-ming's first phone call to China and China's relations with China, China becomes a "neighboring country" The South Korea-US alliance is preferred, Lee Zai-ming's first phone call to China and China's relations with China, China becomes a "neighboring country" world | 2025-06-07
  • The main body of the new air traffic control tower of the third phase of Taiyuan Airport renovation and expansion project was topped off The main body of the new air traffic control tower of the third phase of Taiyuan Airport renovation and expansion project was topped off technology | 2025-06-07
  • Arkansas, USA, hit by a tornado, and many homes were destroyed Arkansas, USA, hit by a tornado, and many homes were destroyed world | 2025-06-07
  • Aurender launches N50 flagship music server: adopts a three-chassis architecture to show super fever design Aurender launches N50 flagship music server: adopts a three-chassis architecture to show super fever design technology | 2025-06-07

©2025 TODAYINFO. ALL RIGHTS RESERVED.