Agents
MCP STDIO Transport RCE: 11 CVEs Across 7,000+ Vulnerable Servers and 150M+ Package Downloads
OX Security researchers disclosed a critical architectural flaw in Anthropic's Model Context Protocol STDIO transport that enables arbitrary command execution via configuration-to-command injection. The vulnerability affects 11 distinct projects including LiteLLM (CVE-2026-30623, patched), Agent Zero (CVE-2026-30624), and Flowise (CVE-2026-40933), with implementations across Python, TypeScript, Java, and Rust. Over 7,000 publicly accessible servers and packages totaling 150M+ downloads are affected. The design flaw allows MCP tool invocations to execute arbitrary OS commands through the STDIO interface, returning error messages after execution regardless of server validity.
↳ Follow the thread