MCP Flaw Shakes 200,000 Servers
Key point
A design flaw in MCP has exposed up to **200,000 instances** to remote code execution risk.
Details
OX Security has disclosed a critical, systemic flaw in Anthropic's Model Context Protocol (MCP).
The flaw was identified not as a bug in a misconfigured individual app, but as a design issue inherent in Anthropic's official MCP SDK (Python, TypeScript, Java, Rust). Attackers can trigger arbitrary command execution on vulnerable systems, gaining access to sensitive user data, internal databases, API keys, and chat history.
The scope of impact was estimated at over 200,000 instances, 7,000 public servers, over 200 open-source projects, and a cumulative 150 million downloads.
OX Security requested a protocol-level patch, but Anthropic reportedly viewed this as expected behaviour and did not fix it.
- Security issues related to MCP continue to accumulate
- OX Security has already conducted over 30 responsible disclosures
- Over 10 high/critical CVEs confirmed across protocol-based projects
- Anthropic's Git MCP server and Claude Code tools were also previously flagged for RCE paths
This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.
Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.