Agents
OX Security Exposes Architectural MCP Design Flaw Enabling RCE Across 150M+ Downloads and 200K Servers — Anthropic Declines to Fix
OX Security published an advisory on April 15 detailing a systemic vulnerability in the MCP STDIO interface: any attacker who can influence an MCP configuration can achieve arbitrary shell command execution on the host, regardless of programming language. Anthropic confirmed the behavior is by design and declined to modify the protocol, stating sanitization is the developer's responsibility. The flaw affects Claude Code, Cursor, VS Code, Windsurf, Gemini CLI, LangChain, LiteLLM, and IBM LangFlow — over 150 million downloads and up to 200,000 vulnerable server instances, with related CVEs already assigned for MCP Inspector, LibreChat, WeKnora, and Cursor.
↳ Follow the thread