Systemic Flaw in MCP Protocol Could Expose 150 Million Downloads
ID: e10a699a-7ffa-5976-a1c9-53c4b90890eb
STIX ID: report--e10a699a-7ffa-5976-a1c9-53c4b90890eb
Feed Name: Infosecurity Magazine (News)
**Critical MCP protocol vulnerability enables arbitrary command execution and potential data exposure:** Ox Security reported an architectural flaw in Anthropic's Model Context Protocol (MCP) STDIO execution model that can execute attacker-supplied commands even when a launched process fails, potentially leading to full system takeover, exposure of sensitive data (API keys, chat histories, internal databases), and broad supply-chain impact across hundreds of projects and up to ~200,000 vulnerable instances; Anthropic has characterized the behavior as "by design" and declined to change the protocol.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
