Design Flaw in Anthropic’s MCP Could Affect More Than 200 Open-Source AI Projects
The Anthropic-led Model Context Protocol, or MCP, allows AI agents to connect to external tools, databases and APIs and has become a foundational interface for agentic AI. OX Security said MCP’s STDIO design executes commands before validation, potentially giving attackers access to data, API keys and conversation logs. Third-party supply-chain risks are particularly significant for banks that allow agents to access financial systems.
OX Security disclosed the issue on April 15, 2026, estimating that it affected more than 200 open-source projects, over 150 million downloads, more than 7,000 publicly accessible servers and as many as 200,000 instances. It also successfully executed commands on six operational platforms. LiteLLM, DocsGPT and Bisheng have issued patches, but Anthropic considers the STDIO mechanism intended behavior and has not changed the protocol. No actual financial losses have been disclosed.
All Coverage
2 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.