Skip to content
Registry/Agents/Model Context Protocol (MCP)
Agent Profile

Model Context Protocol (MCP)

Anthropic

Open protocol and SDKs connecting AI agents to external tools, data sources and servers.

1
Cases
4.0/5
Severity
0
Apr 20, 2026

A design flaw in Anthropic's Model Context Protocol enabled command execution across all four official SDKs

OX Security disclosed a systemic architectural weakness in Anthropic's Model Context Protocol that enables arbitrary command execution across implementations, rooted in unsafe STDIO transport defaults permitting configuration-to-command execution. It affects the MCP SDK in Python, TypeScript, Java and Rust simultaneously, with more than 7,000 publicly accessible servers and over 150 million downloads across downstream projects including LiteLLM, LangChain, LangFlow, Flowise and LettaAI. Successful attacks give access to sensitive data, databases, API keys and chat histories. Anthropic declined to modify the protocol architecture, characterizing the behaviour as expected; some vendors patched independently while the reference implementation remained unaddressed at publication.