Mark RadarMARK RADAR
EN

Design Flaw in Anthropic’s MCP Could Affect More Than 200 Open-Source AI Projects

2 reports · First detected 2026-04-17 · Last active 2026-04-22

The Anthropic-led Model Context Protocol, or MCP, allows AI agents to connect to external tools, databases and APIs and has become a foundational interface for agentic AI. OX Security said MCP’s STDIO design executes commands before validation, potentially giving attackers access to data, API keys and conversation logs. Third-party supply-chain risks are particularly significant for banks that allow agents to access financial systems.

OX Security disclosed the issue on April 15, 2026, estimating that it affected more than 200 open-source projects, over 150 million downloads, more than 7,000 publicly accessible servers and as many as 200,000 instances. It also successfully executed commands on six operational platforms. LiteLLM, DocsGPT and Bisheng have issued patches, but Anthropic considers the STDIO mechanism intended behavior and has not changed the protocol. No actual financial losses have been disclosed.

All Coverage

2 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR
All times are in Taipei time (GMT+8)