Anthropic MCP Hit by Critical Vulnerability Enabling Remote Code Execution
ID: 4c5a26b8-dd99-5a61-a5ac-025e39fbe4f3
STIX ID: report--4c5a26b8-dd99-5a61-a5ac-025e39fbe4f3
Feed Name: GBHackers
OX Security published research revealing an architectural flaw in Anthropic's Model Context Protocol (MCP) SDKs that permits arbitrary remote code execution across Python, TypeScript, Java, and Rust implementations, impacting millions of downloads and up to ~200,000 servers; researchers demonstrated multiple exploitation families (unauthenticated UI injection, zero-click prompt injection, hardening bypasses, and poisoned registries), reported at least ten CVEs (several Critical), confirmed command execution on live platforms, and issued urgent mitigation guidance including network restrictions, treating MCP input as untrusted, sandboxing, and immediate patching.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
