A critical command injection vulnerability in the MCP stdio transport allows authenticated users to execute arbitrary commands on host machines. LiteLLM patched in v1.83.7-stable with a command allowlist restricted to known MCP launchers (npx, uvx, python, node, docker, deno). OX Security's advisory on April 15 revealed the flaw affects the broader MCP ecosystem across 150M+ SDK downloads and 200,000+ servers. Anyone running MCP servers via stdio transport should audit their command validation immediately.