Anthropic's Model Context Protocol has critical flaw exposing 200,000 servers to remote takeover
Security researchers at OX Security discovered a critical architectural vulnerability in Anthropic's Model Context Protocol that enables remote code execution across 200,000 server instances and affects over 150 million downloads. The flaw is baked into MCP's official SDKs across Python, TypeScript, Java, and Rust. Despite repeated requests for a protocol-level fix, Anthropic declined to patch the issue, calling the behavior "expected."