Anthropic's deprecated Slack MCP server could leak data via Slack link unfurling and prompt injection (CVE-2025-34072)
2025-anthropic-slack-mcp-exfiltration · 2025-06-24
A researcher advisory showed that the deprecated Anthropic Slack MCP server could be abused: prompt injection in untrusted content makes an agent post an attacker-crafted link containing sensitive data to Slack, and Slack's automatic link unfurling then fetches it — exfiltrating the data to an attacker server (CVE-2025-34072). The server was archived without a fix.
System
- Framework
- Anthropic Slack MCP server (deprecated / archived)
- Tools
- slack-mcp, slack
- Vendor
- Anthropic
- Autonomy
- supervised-autonomous
Classification
- Primary class
- prompt-injection
- Chain
- prompt-injection/indirect → data-exfiltration/via-tool
- Attack vector
- untrusted-content
- Causation
- entity: human · intentionality: intentional · timing: post-deployment
Trigger
An attacker embeds instructions in untrusted content (a document or code file) that direct the agent to post a specially crafted hyperlink — containing sensitive data in its query parameters — into a Slack channel. Slack automatically unfurls the link to render a preview, issuing an HTTP request to the attacker-controlled URL and leaking the embedded data.
Root cause
Two behaviours combine: the agent acts on instructions from untrusted content, and Slack's automatic link unfurling turns any agent-posted URL into an outbound request. Data placed in a posted link is exfiltrated without any additional user action.
Contributing factors
- Link unfurling was enabled, turning posted URLs into automatic outbound requests.
- The agent treated instructions in untrusted content as actionable.
- The MCP server was deprecated and unmaintained, so no fix was planned despite continued use.
Detection
Discovered and disclosed by researcher Johann Rehberger (wunderwuzzi); reported on 2025-05-27 and published on 2025-06-24. Assigned CVE-2025-34072.
Recovery
The server had been archived on 2025-05-29 with no plan to address vulnerabilities; the advised mitigation is to disable Slack unfurling (unfurl_links: false, unfurl_media: false).
Prevention
Disable automatic link unfurling for agent-posted content; treat tool/file content as untrusted; prevent agents from placing data into outbound URLs; retire or replace deprecated MCP servers that remain in use.
Blast radius
- Data
- Secrets and API keys from files (e.g. .env), private data, and internal company data could be encoded into a posted link and exfiltrated via Slack unfurling. credentials
- User harm
- A disclosed vulnerability in a deprecated server; no confirmed in-the-wild exploitation was reported. none-reported
- Scope
- users of the deprecated Anthropic Slack MCP server (14k+ weekly npm downloads)
- Reversibility
- reversible
References
- OWASP LLM
- LLM01 LLM02
- MITRE ATLAS
- AML.T0024 AML.T0051
- Related
- 2025-whatsapp-mcp-tool-poisoning 2025-echoleak-m365-copilot 2025-claude-code-dns-exfiltration
- Tags
- mcp slack data-exfiltration link-unfurling deprecated cve
Sources
Cite this incident
Permalink: https://swarmproof.github.io/agent-postmortems/2025-anthropic-slack-mcp-exfiltration/
@misc{2025-anthropic-slack-mcp-exfiltration,
title = {Anthropic's deprecated Slack MCP server could leak data via Slack link unfurling and prompt injection (CVE-2025-34072)},
year = {2025},
howpublished = {agent-postmortems},
url = {https://swarmproof.github.io/agent-postmortems/2025-anthropic-slack-mcp-exfiltration/}
}