logo

Critical Anthropic MCP Vulnerability Enables Remote Code Execution Attacks

ID: cebf7408-3be4-5494-8c7d-4451c532c907

STIX ID: report--cebf7408-3be4-5494-8c7d-4451c532c907

Feed Name: Cyber Press

Threat Score
90/100

Date Published: 2026-04-20

Date Updated: 2026-05-05

Author: AnuPriya

...
...

A critical architectural flaw in Anthropic's Model Context Protocol (MCP) SDKs—affecting Python, TypeScript, Java, Rust and other environments—was disclosed by OX Security; the weakness enables remote code execution, access to internal databases, API keys, and chat histories, and has multiple exploitation paths (unauthenticated UI injection, zero-click prompt injection, registry-based payload distribution). Researchers reported at least 10 CVEs (many critical), successful remote command execution on live platforms, and widespread exposure across downloads and servers; Anthropic has not applied a protocol-level fix, and mitigations such as blocking public access, sandboxing, and treating MCP inputs as untrusted are recommended.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.