PT-2025-27630 · Anthropic · Slack Model Context Protocol (Mcp) Server

Wunderwuzzi

·

Published

2025-06-24

·

Updated

2025-07-02

·

CVE-2025-34072

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions: Anthropic’s Slack Model Context Protocol (MCP) Server (affected versions not specified)
Description: A data exfiltration issue exists in the deprecated Slack Model Context Protocol (MCP) Server via automatic link unfurling. When an AI agent using the Slack MCP Server processes untrusted data, it can be manipulated to generate messages containing attacker-crafted hyperlinks embedding sensitive data. Slack’s link preview bots will then issue outbound requests to the attacker-controlled URL, resulting in zero-click exfiltration of private data.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Information Disclosure

RCE

Weakness Enumeration

Related Identifiers

BDU:2025-13140
CVE-2025-34072

Affected Products

Slack Model Context Protocol (Mcp) Server