Critical MCP SDK Flaw Exposed 200,000 Instances to Arbitrary Shell Command Execution
On April 15, 2026, security firm OX Security disclosed a vulnerability, now tracked as CVE-2026-30623, affecting all four official Model Context Protocol SDKs — Python, TypeScript, Java, and Rust. The flaw, embedded in MCP's STDIO transport layer, allows anyone who can modify a server configuration file to execute arbitrary shell commands on the host machine, even if the target server never launches. Anthropic acknowledged the behavior but declined to change it, leaving over 200,000 vulnerable instances exposed across a supply chain exceeding 150 million downloads. The risk is amplified by how easily MCP config blocks are copy-pasted without security review, compressing what previously required custom code and peer sign-off into a single JSON entry. A partial fix is expected to ship on July 28, 2026, and developers are advised to audit their configured servers for STDIO transports carrying unsanitized environment credentials.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in