Skip to main content
AI Security

Security researchers warn 200,000 MCP servers are vulnerable to command injection

Security researchers warn 200,000 MCP servers are vulnerable to command injection Image: Primary
Anthropic created the Model Context Protocol as the open standard for AI agent-to-tool communication. OpenAI adopted it in March 2025. Google DeepMind followed. Anthropic donated MCP to the Linux Foundation in December 2025. Downloads crossed 150 million. Then four researchers at OX Security found an architectural problem that affects all of them. MCP's STDIO transport, the default for connecting an AI agent to a local tool, executes any operating system command it receives with no sanitization and no execution boundary between configuration and command. A malicious command returns an error after the command has already run. The developer toolchain raises no flag. OX Security researchers Moshe Siman Tov Bustan, Mustafa Naamnih, Nir Zadok and Roni Bar scanned the ecosystem and found 7,000 servers on public internet protocol addresses with STDIO transport active. They estimate 200,000 total vulnerable instances extrapolated from that ratio. They confirmed arbitrary command execution on six live production platforms with paying customers. The research produced more than 10 common vulnerabilities and exposures rated high or critical across LiteLLM, LangFlow, Flowise, Windsurf, LangChain-Chatchat, Bisheng, DocsGPT, GPT Researcher, Agent Zero, and LettaAI. Kevin Curran, an Institute of Electrical and Electronics Engineers senior member and professor of cybersecurity at Ulster University, independently told Infosecurity Magazine the research exposed a shocking gap in the security of foundational AI infrastructure. Anthropic confirmed the behavior is by design and declined to modify the protocol. The company characterized STDIO's execution model as a secure default and input sanitization as the developer's responsibility. OX says expecting 200,000 developers to sanitize inputs correctly is the problem. Anthropic's strongest technical counter is that sanitizing STDIO would either break the transport or move the payload one layer down. If teams deployed any MCP-connected AI agent using the default STDIO transport, they are exposed. The insecurity is not a coding bug in any single product. It is a design default in Anthropic's MCP specification that propagated into every official language software development kit: Python, TypeScript, Java, and Rust. Every downstream project that trusted the protocol inherited it. OX identified four exploitation families. Unauthenticated command injection through AI framework web interfaces was demonstrated against LangFlow and LiteLLM.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from VentureBeat and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
AI Capital
AI Capital

Tandem Health raises €86.49 million for European clinic AI platform

Stockholm-based Tandem Health has raised €86.49 million ($100 million) in a Series B led by EQT-managed Scaleup Europe Fund, bringing its total funding to €138.38 million. Tandem said its medical-assistant software supports clinic...

AI Capital
AI Capital

Aeon acquires Aware Health after Seed extension tops €12 million

Zurich preventive-health company Aeon has acquired German blood-diagnostics platform Aware Health and closed a Seed extension that brings its total Seed funding above €12 million. Aeon said it acquired Aware's technology platform,...

Robotics Infrastructure
Robotics Infrastructure

MIT spinout deploys recycled-plastic composite trusses for Army Corps bridge

MIT spinout Atlas Building Composites has supplied recycled-composite trusses for a 40-foot bridge built by the U.S. Army Corps of Engineers in a Massachusetts wetland. Atlas uses waterless plastic recycling, fiberglass reinforcem...

Infrastructure Capital
Infrastructure Capital

Firmus reportedly seeks up to $5 billion in Australian IPO

Firmus Technologies is looking to raise as much as $5 billion in an initial public offering in Australia, according to people familiar with the matter. The report describes a prospective capital raise rather than a completed listi...

Infrastructure Products
Infrastructure Products

AI data-center developers offer communities more to win approvals

Amazon, Microsoft, Oracle and other AI data-center developers are sweetening financial offers to municipalities and regulators as they seek approval for new facilities, according to The Information. The report says hyperscalers ar...