/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Researchers detail an exploit in GitHub's official MCP server that lets hackers trick an LLM agent into leaking private information about the MCP user

Attackers only need to open a malicious issue on the targeted repositories to exploit the vulnerability.  —  invariantlabs.ai/blog/mcp-git... Daniel Cuthbert / @dcuthbert : We are truly back in the 1990s when it comes to validation and processing said dirty data  —  invariantlabs.ai/blog/mcp-git... Lukasz Olejnik / @lukaszolejnik : CRITICAL vulnerability in AI software engineering layer (MCP server of Github).  Expect many, many more of such issues.  This is a first real-world demonstration of how agents can be hijacked, leaking secret or private data. invariantlabs.ai/blog/mcp-git...  [image] Kenn White / @kennwhite : Just the tip of the iceberg from this roll-your-own security protocol.  We're about to usher in a golden age of Valhalla-level AI pwnage, and it'll be riding on the coattails of badly designed agents.  —  invariantlabs.ai/blog/mcp-git... Simon Willison / @simonwillison.net : GitHub MCP suffers from the lethal trifecta for prompt injection: access to private data, exposure to malicious instructions + the ability to exfiltrate information  —  Be really careful with this stuff: attackers can trick your “agent” into stealing your private data simonwillison.net/2025/May/26/ ... … Mastodon: @tante@tldr.nettime.org : This is just one example.  “MCP” the protocol for “AI agents” is basically without security measures.  It's like running random code on your infrastructure and data.  —  (Original title: GitHub MCP Exploited: Accessing private repositories via MCP)  —  https://simonwillison.net/... @mttaggart@infosec.exchange : Lol, lmao, etc.  —  You know at some point putting things on GitHub has to be considered a liability.  —  https://invariantlabs.ai/... Mike Sax / @mikesax@mas.to : “My best advice is to be **very careful** if you're experimenting with MCP as an end-user.”  — @simon willison  —  https://simonwillison.net/... Simon Willison / @simon@fedi.simonwillison.net : The GitHub MCP server suffers from the lethal trifecta for prompt injection: access to private data, exposure to malicious instructions + the ability to exfiltrate information  —  Be really careful with this stuff: attackers can trick your “agent” into stealing your private data https://simonwillison.net/... X: Luca Beurer-Kellner / @lbeurerkellner : 😈 BEWARE: Claude 4 + GitHub MCP will leak your private GitHub repositories, no questions asked. We discovered a new attack on agents using GitHub's official MCP server, which can be exploited by attackers to access your private repositories. creds to @marco_milanta (1/n) 👇 [image] John Halloran / @convexdad : @lbeurerkellner @marco_milanta Interesting, good find. We found similar privacy leakage issues with the Slack MCP server, which could even be compromised through external manipulation. Attacks go beyond privacy leakage, e.g., remote systems access. More details: https://www.arxiv.org/... Forums: Hacker News : GitHub MCP exploited: Accessing private repositories via MCP r/programming : GitHub MCP Exploited: Accessing private repositories via MCP Lobsters : GitHub MCP Exploited: Accessing private repositories via MCP

Simon Willison's Weblog Simon Willison

Discussion

  • @campuscodi.risky.biz Catalin Cimpanu on bluesky
    A vulnerability in the official GitHub MCP server can allow attackers to hijack GitHub AI agents and leak data or run malicious code inside private repositories  —  Attackers only need to open a malicious issue on the targeted repositories to exploit the vulnerability.  —  invari…
  • @dcuthbert Daniel Cuthbert on bluesky
    We are truly back in the 1990s when it comes to validation and processing said dirty data  —  invariantlabs.ai/blog/mcp-git...
  • @lukaszolejnik Lukasz Olejnik on bluesky
    CRITICAL vulnerability in AI software engineering layer (MCP server of Github).  Expect many, many more of such issues.  This is a first real-world demonstration of how agents can be hijacked, leaking secret or private data. invariantlabs.ai/blog/mcp-git...  [image]
  • @kennwhite Kenn White on bluesky
    Just the tip of the iceberg from this roll-your-own security protocol.  We're about to usher in a golden age of Valhalla-level AI pwnage, and it'll be riding on the coattails of badly designed agents.  —  invariantlabs.ai/blog/mcp-git...
  • @simonwillison.net Simon Willison on bluesky
    GitHub MCP suffers from the lethal trifecta for prompt injection: access to private data, exposure to malicious instructions + the ability to exfiltrate information  —  Be really careful with this stuff: attackers can trick your “agent” into stealing your private data simonwillis…
  • @lbeurerkellner Luca Beurer-Kellner on x
    😈 BEWARE: Claude 4 + GitHub MCP will leak your private GitHub repositories, no questions asked. We discovered a new attack on agents using GitHub's official MCP server, which can be exploited by attackers to access your private repositories. creds to @marco_milanta (1/n) 👇 [image…
  • @convexdad John Halloran on x
    @lbeurerkellner @marco_milanta Interesting, good find. We found similar privacy leakage issues with the Slack MCP server, which could even be compromised through external manipulation. Attacks go beyond privacy leakage, e.g., remote systems access. More details: https://www.arxiv…
  • r/programming r on reddit
    GitHub MCP Exploited: Accessing private repositories via MCP