logo

Anthropic won't own MCP 'design flaw' putting 200K servers at risk, researchers say

ID: e286d228-acc7-5158-a6fd-9acf277a6130

STIX ID: report--e286d228-acc7-5158-a6fd-9acf277a6130

Feed Name: The Register (Security)

Threat Score
78/100

Date Published: 2026-04-16

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Ox security researchers disclosed a design flaw in Anthropic's open-source Model Context Protocol (MCP) that allows attackers to execute arbitrary OS commands and achieve full RCE across many AI frameworks, SDKs, and developer tools. The team demonstrated four vulnerability classes—including unauthenticated/authenticated command injection, hardening bypasses, zero-click prompt injection, and MCP marketplace poisoning—reported multiple CVEs and proof-of-concept exploits, and said Anthropic declined to implement a protocol-level fix, leaving large numbers of downstream projects and users at risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.