Agents
Ox Security Discloses Systemic MCP STDIO Command Injection Affecting 150M Downloads; Anthropic Calls It 'Expected Behavior'
Ox Security published a full advisory on April 15 revealing that MCP's STDIO transport accepts arbitrary command strings and passes them directly to subprocess execution across all official SDKs (Python, TypeScript, Java, Rust). The command executes even when the MCP server fails to start — 'execute first, validate never.' Ox demonstrated exploitation on six production platforms, took over thousands of public servers across 200+ open-source projects, and uploaded proof-of-concept malicious servers to 9 of 11 major MCP marketplaces. Anthropic responded that this is 'expected behavior.' Impact: 150M+ downloads, 200K+ vulnerable instances.
↳ Follow the thread