CVE-2025-34072
Anthropic Slack MCP Server Data Exfiltration via Link Unfurling
Severity Score
9.3
*CVSS v4
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
1
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
Track*
*SSVC
Descriptions
A data exfiltration vulnerability exists in Anthropic’s deprecated Slack Model Context Protocol (MCP) Server via automatic link unfurling. When an AI agent using the Slack MCP Server processes untrusted data, it can be manipulated to generate messages containing attacker-crafted hyperlinks embedding sensitive data. Slack’s link preview bots (e.g., Slack-LinkExpanding, Slackbot, Slack-ImgProxy) will then issue outbound requests to the attacker-controlled URL, resulting in zero-click exfiltration of private data.
*Credits:
wunderwuzzi of Embrace The Red
CVSS Scores
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
System
Vulnerable | Subsequent
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:Track*
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2025-04-15 CVE Reserved
- 2025-07-02 CVE Published
- 2025-07-02 CVE Updated
- 2025-07-02 First Exploit
- ---------- EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-20: Improper Input Validation
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
- CAPEC-34: HTTP Response Splitting
References (2)
URL | Tag | Source |
---|---|---|
https://vulncheck.com/advisories/anthropic-slack-mcp-server-data-exfiltration | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://embracethered.com/blog/posts/2025/security-advisory-anthropic-slack-mcp-server-data-leakage | 2025-07-02 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Anthropic Search vendor "Anthropic" | Slack MCP Server Search vendor "Anthropic" for product "Slack MCP Server" | 0 Search vendor "Anthropic" for product "Slack MCP Server" and version "0" | en |
Affected
|