agent-postmortems a structured database of real AI-agent failures

← all incidents

hazard high confidence: confirmed status: final

Anthropic's deprecated Slack MCP server could leak data via Slack link unfurling and prompt injection (CVE-2025-34072)

2025-anthropic-slack-mcp-exfiltration · 2025-06-24

A researcher advisory showed that the deprecated Anthropic Slack MCP server could be abused: prompt injection in untrusted content makes an agent post an attacker-crafted link containing sensitive data to Slack, and Slack's automatic link unfurling then fetches it — exfiltrating the data to an attacker server (CVE-2025-34072). The server was archived without a fix.

System

Framework
Anthropic Slack MCP server (deprecated / archived)
Tools
slack-mcp, slack
Vendor
Anthropic
Autonomy
supervised-autonomous

Classification

Primary class
prompt-injection
Chain
prompt-injection/indirect → data-exfiltration/via-tool
Attack vector
untrusted-content
Causation
entity: human · intentionality: intentional · timing: post-deployment

Trigger

An attacker embeds instructions in untrusted content (a document or code file) that direct the agent to post a specially crafted hyperlink — containing sensitive data in its query parameters — into a Slack channel. Slack automatically unfurls the link to render a preview, issuing an HTTP request to the attacker-controlled URL and leaking the embedded data.

Root cause

Two behaviours combine: the agent acts on instructions from untrusted content, and Slack's automatic link unfurling turns any agent-posted URL into an outbound request. Data placed in a posted link is exfiltrated without any additional user action.

Contributing factors

  • Link unfurling was enabled, turning posted URLs into automatic outbound requests.
  • The agent treated instructions in untrusted content as actionable.
  • The MCP server was deprecated and unmaintained, so no fix was planned despite continued use.

Detection

Discovered and disclosed by researcher Johann Rehberger (wunderwuzzi); reported on 2025-05-27 and published on 2025-06-24. Assigned CVE-2025-34072.

Recovery

The server had been archived on 2025-05-29 with no plan to address vulnerabilities; the advised mitigation is to disable Slack unfurling (unfurl_links: false, unfurl_media: false).

Prevention

Disable automatic link unfurling for agent-posted content; treat tool/file content as untrusted; prevent agents from placing data into outbound URLs; retire or replace deprecated MCP servers that remain in use.

Blast radius

Data
Secrets and API keys from files (e.g. .env), private data, and internal company data could be encoded into a posted link and exfiltrated via Slack unfurling. credentials
User harm
A disclosed vulnerability in a deprecated server; no confirmed in-the-wild exploitation was reported. none-reported
Scope
users of the deprecated Anthropic Slack MCP server (14k+ weekly npm downloads)
Reversibility
reversible

References

OWASP LLM
LLM01 LLM02
MITRE ATLAS
AML.T0024 AML.T0051
Tags
mcp slack data-exfiltration link-unfurling deprecated cve

Sources

Cite this incident

@misc{2025-anthropic-slack-mcp-exfiltration,
  title = {Anthropic's deprecated Slack MCP server could leak data via Slack link unfurling and prompt injection (CVE-2025-34072)},
  year = {2025},
  howpublished = {agent-postmortems},
  url = {https://swarmproof.github.io/agent-postmortems/2025-anthropic-slack-mcp-exfiltration/}
}