Critical Anthropic MCP Vulnerability Enables Remote Code Execution Attacks
ID: cebf7408-3be4-5494-8c7d-4451c532c907
STIX ID: report--cebf7408-3be4-5494-8c7d-4451c532c907
Feed Name: Cyber Press
A critical architectural flaw in Anthropic's Model Context Protocol (MCP) SDKs—affecting Python, TypeScript, Java, Rust and other environments—was disclosed by OX Security; the weakness enables remote code execution, access to internal databases, API keys, and chat histories, and has multiple exploitation paths (unauthenticated UI injection, zero-click prompt injection, registry-based payload distribution). Researchers reported at least 10 CVEs (many critical), successful remote command execution on live platforms, and widespread exposure across downloads and servers; Anthropic has not applied a protocol-level fix, and mitigations such as blocking public access, sandboxing, and treating MCP inputs as untrusted are recommended.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
