Fetching from the wire…
Security2026-04-30 · source-backed
OX Security researchers found a design-level flaw in Anthropic's Model Context Protocol STDIO transport that turns MCP tool invocations into OS command execution via configuration-to-command injection. Affected projects include LiteLLM (CVE-2026-30623, patched), Agent Zero, and Flowise across Python, TypeScript, Java, and Rust. If you run MCP servers, audit your STDIO configurations immediately. This isn't a theoretical risk.
Each link below shares sources, entities, or timing with this story.
OX Security criticizes MCP / Shared entities / Shared topic / What happened next
Linked by a graph relationship (OX Security criticizes MCP); both cover Anthropic, Java, MCP, OX Security; overlapping topics (agent, anthropic, context).
OX Security criticizes MCP / Shared entities / Same source domain / Shared topic / What happened next
Linked by a graph relationship (OX Security criticizes MCP); both cover CVE, CVEs, LiteLLM, MCP; reported by the same outlet (thehackernews.com).
OX Security criticizes MCP / Shared entities / Shared topic / What happened next
Linked by a graph relationship (OX Security criticizes MCP); both cover Anthropic, CVEs, MCP, OX Security; overlapping topics (anthropic, audit, command, cves, download).
OX Security criticizes MCP / Shared entities / Shared topic / Earlier coverage
Linked by a graph relationship (OX Security criticizes MCP); both cover Anthropic, CVE, CVEs, MCP; overlapping topics (anthropic, arbitrary, audit, command, cves).
OX Security criticizes MCP / Shared entities / Shared topic / What happened next
Linked by a graph relationship (OX Security criticizes MCP); both cover Anthropic, CVE, LiteLLM, MCP; overlapping topics (anthropic, arbitrary, audit, command, configuration).
OX Security criticizes MCP / Shared entities / Same source domain / What happened next
Linked by a graph relationship (OX Security criticizes MCP); both cover Anthropic, CVE, MCP, Python; reported by the same outlet (thehackernews.com).
OX Security criticizes MCP / Shared entities / Shared topic / What happened next
Linked by a graph relationship (OX Security criticizes MCP); both cover Anthropic, CVEs, MCP, STDIO; overlapping topics (audit, execution, server).
OX Security criticizes MCP / Shared entities / Shared topic / Earlier coverage / Tension
Linked by a graph relationship (OX Security criticizes MCP); both cover Anthropic, CVE, CVEs, MCP; overlapping topics (cves, server).