Skip to content

Science1 publisher3 min readPublished

OX Security says MCP command execution is a design choice, so server owners own the risk

The vendor reports 10-plus CVEs and up to 200,000 exposed instances, and says Anthropic declined to change the protocol, describing the behaviour as expected.

The Scientist · Science desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying OX Security says MCP command execution is a design choice, so server owners own the risk
Generated illustration

What happened

  • The OX Security Research team says it uncovered a critical, systemic vulnerability at the core of the Model Context Protocol (MCP), the industry standard for AI agent communication created and maintained by Anthropic.
  • OX Security says the flaw enables arbitrary command execution (RCE) on any system running a vulnerable MCP implementation, granting attackers direct access to sensitive user data, internal databases, API keys and chat histories.
  • OX Security says this is not a traditional coding error but an architectural design decision baked into Anthropic's official MCP SDKs across every supported programming language, including Python, TypeScript, Java and Rust, and that any developer building on the Anthropic MCP foundation unknowingly inherits the exposure.
  • OX Security states the vulnerability ripples through a supply chain with 150M+ downloads, 7,000+ publicly accessible servers, and up to 200,000 vulnerable instances in total.
  • OX Security identifies four distinct families of exploitation: unauthenticated UI injection in popular AI frameworks; hardening bypasses in 'protected' environments like Flowise; zero-click prompt injection in leading AI IDEs (Windsurf, Cursor); and malicious marketplace distribution.

Compiled by The ScientistSomething wrong?How this is made

Why it matters

OX Security has published research claiming a systemic remote command execution exposure at the core of the Model Context Protocol, the agent communication standard created and maintained by Anthropic [1]. The company's framing matters more than the individual bugs: it says this is not a coding error but an architectural decision present in Anthropic's official MCP SDKs across Python, TypeScript, Java and Rust, so anyone building on that foundation inherits the exposure [3].

According to OX, a vulnerable MCP implementation can be driven into arbitrary command execution, giving an attacker access to user data, internal databases, API keys and chat histories [2]. The company puts the blast radius at more than 150 million SDK downloads, more than 7,000 publicly reachable servers, and up to 200,000 vulnerable instances in total [4]. It says it grouped exploitation into four families: unauthenticated UI injection in popular AI frameworks, hardening bypasses in supposedly protected environments such as Flowise, zero-click prompt injection in AI IDEs including Windsurf and Cursor, and malicious distribution through registries [5]. On the last route, OX reports it successfully planted a malicious trial balloon in 9 of 11 MCP registries [6], roughly 82 percent of the registries it tested [17].

The vendor also says it executed commands on six live production platforms and found critical vulnerabilities in LiteLLM, LangChain and IBM's LangFlow [7], through more than 30 disclosures and 10 or more High or Critical CVEs [8]. OX states it recommended root patches to Anthropic, that Anthropic declined to modify the protocol's architecture and described the behaviour as expected, and that the root cause therefore remains unaddressed at the protocol level [9][11]. OX adds that it told Anthropic it intended to publish and that Anthropic raised no objection [10]. Anthropic's position here is reported only through OX; the source material contains no direct statement from Anthropic, and the phrase "expected" is OX's characterisation of the exchange [9].

For operators, the practical consequence is the same whether or not the protocol changes. OX's own guidance is to treat any external MCP configuration input as untrusted, on the assumption that user input reaching StdioServerParameters or similar functions is directly equivalent to command execution, and either to block it outright or to permit only trusted pre-configured commands [12]. The rest of its list is conventional containment: keep LLM tooling off public IPs, install servers only from verified sources such as the official GitHub MCP Registry, sandbox MCP-enabled services rather than granting full disk or shell access, watch which tools agents actually invoke and where they send data, and upgrade or disable affected services [13]. That is a configuration and deployment problem, owned by whoever ships the server, not a queue position behind an upstream fix.

OX has also productised the finding, saying its platform now detects user input flowing into STDIO-based MCP configuration in AI-generated code and flags existing STDIO MCP configurations in customer codebases [14]. That is worth reading as commercial interest as well as research.

Two things to watch. First, whether the CVE count continues to climb through individual downstream projects while the SDK behaviour stays as it is [8][11]. Second, whether Anthropic responds on architecture; OX explicitly ties its request for a secure-by-design change to Anthropic's launch last week of Claude Mythos, pitched at securing the world's software [15].

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories