Anthropic MCP SDK Flaw Allows Remote Code Execution

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Anthropic's Model Context Protocol (MCP) SDK contains a "by design" flaw that allows arbitrary OS command execution via the STDIO interface, according to OX Security researchers.
- OX Security disclosed ten related CVEs across projects like LiteLLM, LangChain, and Flowise, affecting over 7,000 public servers and more than 150 million downloads.
- CVE‑2025‑65720 (GPT Researcher) and other CVEs (e.g., CVE‑2026‑30623, CVE‑2026‑30624) were identified, with some already patched (LiteLLM, Bisheng, DocsGPT).
- Anthropic has refused to change the MCP architecture, calling the behavior “expected,” leaving the vulnerability in its reference implementation.
- Developers are urged to block public IP access, sandbox MCP services, treat external configuration as untrusted, and install MCP servers only from verified sources.
- MCP's single architectural decision propagated across languages and downstream libraries, creating a broad attack surface for AI‑powered integrations.
Why it matters: Developers and enterprises using Anthropic's MCP face immediate risk of data theft, system compromise, and loss of API keys, while Anthropic avoids costly redesign by labeling the behavior expected, shifting the burden to downstream implementers and leaving the broader AI supply chain exposed.



