logo

Systemic Flaw in MCP Protocol Could Expose 150 Million Downloads

ID: e10a699a-7ffa-5976-a1c9-53c4b90890eb

STIX ID: report--e10a699a-7ffa-5976-a1c9-53c4b90890eb

Feed Name: Infosecurity Magazine (News)

Threat Score
85/100

Date Published: 2026-04-16

Date Updated: 2026-04-22

...
...

**Critical MCP protocol vulnerability enables arbitrary command execution and potential data exposure:** Ox Security reported an architectural flaw in Anthropic's Model Context Protocol (MCP) STDIO execution model that can execute attacker-supplied commands even when a launched process fails, potentially leading to full system takeover, exposure of sensitive data (API keys, chat histories, internal databases), and broad supply-chain impact across hundreds of projects and up to ~200,000 vulnerable instances; Anthropic has characterized the behavior as "by design" and declined to change the protocol.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.