Critical Anthropic MCP Vulnerability Enables Remote Code Execution Attacks
The flaw, which affects MCP implementations across multiple programming environments, could enable attackers to execute arbitrary code remotely and gain access to sensitive data.
Researchers estimate the exposure impacts over 150 million MCP-related downloads and up to 200,000 active servers.
The vulnerability allows attackers to access internal databases, API keys, chat histories, and other confidential information without requiring user interaction in some cases.
Unlike traditional security flaws, this issue is not caused by a coding mistake. Instead, OX Security identified it as a fundamental architectural weakness embedded in Anthropic’s official MCP software development kits (SDKs).
The flaw exists across all supported languages, including Python, TypeScript, Java, and Rust, meaning any developer using MCP may unknowingly inherit the risk through their software supply chain.
OX Security researchers uncovered four primary attack methods tied to the vulnerability:
The team confirmed successful remote command execution on six live production platforms. Additional vulnerabilities were identified in popular tools, including LiteLLM, LangChain, and IBM’s LangFlow.
The research led to the disclosure of at least 10 vulnerabilities, many rated critical.
Notable examples include:
Despite responsible disclosure efforts, the root issue remains unresolved at the protocol level.
OX Security reported that Anthropic classified the behavior as “expected,” declining to implement immediate architectural fixes.
Security teams are urged to take immediate action to reduce exposure:
OX Security has introduced new detection capabilities to identify insecure MCP configurations and flag vulnerable code in enterprise environments.
The researchers also pointed to Anthropic’s recent launch of Claude Mythos, a tool designed to improve software security, urging the company to adopt a “secure by design” approach within its own MCP ecosystem.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google
The post Critical Anthropic MCP Vulnerability Enables Remote Code Execution Attacks appeared first on Cyber Security News.
If you still don’t own a PS5, the Digital Edition Fortnite Flowering Chaos Bundle avoids…
Few tools are as useful for simple cleaning and maintenance than a powerful air duster.…
A newly disclosed vulnerability in the popular iTerm2 macOS terminal emulator shows that even viewing…
Illustration by Heather Landis An ALPR snaps photos of passing cars. Its purpose is to…
Photo by Joan Marcus/Disney Many Broadway actors leave once a contract is up. You’ve been…
With prices of electric bikes reaching an all-time low, it's time to retire that pedal-powered…
This website uses cookies.