Lemmy.zip
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
N7x@infosec.pub to appsec@infosec.pubEnglish ·
edit-2
5 months ago

GitHub MCP Exploited: Accessing private repositories via MCP

invariantlabs.ai

external-link
message-square
1
link
fedilink
  • cross-posted to:
  • [email protected]
2
external-link

GitHub MCP Exploited: Accessing private repositories via MCP

invariantlabs.ai

N7x@infosec.pub to appsec@infosec.pubEnglish ·
edit-2
5 months ago
message-square
1
link
fedilink
  • cross-posted to:
  • [email protected]
We showcase a critical vulnerability with the official GitHub MCP server, allowing attackers to access private repository data. The vulnerability is among the first discovered by Invariant's security analyzer for detecting toxic agent flows.
alert-triangle
You must log in or # to comment.
  • N7x@infosec.pubOP
    link
    fedilink
    English
    arrow-up
    1
    ·
    5 months ago

    Updated the link that was incorrect

appsec@infosec.pub

appsec@infosec.pub

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: [email protected]

A community for all things related to application security.

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 3 users / day
  • 2 users / week
  • 3 users / month
  • 8 users / 6 months
  • 4 local subscribers
  • 370 subscribers
  • 41 Posts
  • 2 Comments
  • Modlog
  • mods:
  • laszlok@infosec.pub
  • BE: 0.19.13
  • Modlog
  • Legal
  • Instances
  • Docs
  • Code
  • join-lemmy.org