‘This is not a traditional coding error’: Experts point to potentially critical security issues at the heart of Anthropic’s MCP, exposing 150 million downloads and thousands of servers to finalize.


  • Ox Researchers Warn Anthropic’s Model Context Protocol Has Systemic RCE Flaw
  • Vulnerability integrated into MCP SDKs on Python, TypeScript, Java, Rust
  • More than 200,000 instances exposed; Anthropic says behavior is ‘expected’

Security researchers Ox have claimed that Anthropic’s Model Context Protocol (MCP) contains a “critical systemic vulnerability” that puts hundreds of thousands of instances at risk of remote code execution (RCE).

Anthropic, on the other hand, reportedly stated that the system worked as expected.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top