CVE-2025-34072: Anthropic Slack MCP Server Data Exfiltration via Link Unfurling
A data exfiltration vulnerability exists in Anthropic’s deprecated Slack Model Context Protocol (MCP) Server via automatic link unfurling. When an AI agent using the Slack MCP Server processes untrusted data, it can be manipulated to generate messages containing attacker-crafted hyperlinks embedding sensitive data. Slack’s link preview bots (e.g., Slack-LinkExpanding, Slackbot, Slack-ImgProxy) will then issue outbound requests to the attacker-controlled URL, resulting in zero-click exfiltration of private data.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-34072?
CVE-2025-34072 is categorized as a high severity vulnerability due to its potential for data exfiltration.
How do I fix CVE-2025-34072?
To mitigate CVE-2025-34072, it is advised to update or disable the Anthropic Slack MCP Server until a patched version is available.
What impact does CVE-2025-34072 have on users?
CVE-2025-34072 can lead to unauthorized access and leakage of sensitive data through manipulated messages.
What versions of Anthropic Slack MCP Server are affected by CVE-2025-34072?
CVE-2025-34072 affects all versions of the Anthropic Slack MCP Server that utilize the deprecated model.
How does CVE-2025-34072 allow for data exfiltration?
CVE-2025-34072 allows for data exfiltration via automatic link unfurling when untrusted data is processed by the Slack MCP Server.