Breaking News: Shai-Hulud Outbreak Debrief: The Worm Evolves into MCP
Read the Report
OX Security is recognized as a Leader in the 2026 Gartner® Magic Quadrant™
Read the full report
OX Security Named a Sample Vendor Across 3 Categories in the Gartner® Hype Cycle™ for Application Security
Read More

150M+ Anthropic Downloads Exposed to Takeover

The Mother of All AI Supply Chains, a “by design” failure at the heart of the AI ecosystem.
150M+ Anthropic downloads exposed to takeover (2)

Get the Cheat Sheet

Key findings:

A systemic flaw at the core of MCP.

A design choice in the Model Context Protocol’s STDIO handling enables unauthenticated command injection and complete server takeover.

Massive exposure.

50M+ downloads and 200K+ exposed servers are affected, with 10+ CVEs and counting.

Deeply embedded across the ecosystem.

The weakness reaches widely used MCP SDKs and tools, including FastMCP, Agno, Letta, LangFlow, and Flowise, and Windsurf allowed zero-click RCE.

Vendors called it “by design.”

Anthropic, LangChain, and FastMCP responses shifted the risk downstream to the organizations that adopted these tools.

If you don’t know which MCP-enabling tools are running in your developer environment, you can’t rule out this exposure.

OX Security research demonstrated how a single malicious MCP server configuration can execute arbitrary commands on a host. Because the underlying behavior was deemed “by design,” the burden of mitigation falls on the organizations that deployed these tools, often without any inventory of what is actually running.

Inside the report:

  • How a malicious MCP server configuration triggers command execution on the host, the STDIO design flaw.
  • The scope of exposure: 150M+ downloads, 200K+ servers, 10+ CVEs.
  • Affected SDKs and tools: FastMCP, Agno, Letta, LangFlow, Flowise, Windsurf, and others.
  • How IDE behavior differs: Windsurf allowed zero-click RCE, while Copilot showed an explicit warning.
  • Coordinated disclosure across 30+ reports and 200+ open-source projects; 9 of 11 marketplaces failed to block a malicious server.

By the numbers:

150M+ downloads exposed.

200K+ exposed servers.

10+ CVEs and counting.

30+ coordinated disclosures • 200+ affected OSS projects • 9 of 11 marketplaces failed.

"The OX Security platform is a game changer for application security teams. It is easy to adopt and integrate into the CI/CD pipeline and provides us the visibility and focus we need to develop fast and secure."

Moshe Belostosky Director of Infrastructure at

"OX Security supports our need for transparency and end to end traceability, ensuring security throughout our processes. This provides us with greater control - blocking vulnerabilities and improving accuracy during the development lifecycle."

Danny Wishlitzky Head of IT and Cybersecurity, CISO, DPO, Proximity

OX is changing the software supply chain security game. It gives a complete and reliable snapshot of code security before deployment

Golan Barash CISO at 888 holdings

Change the trajectory of your entire security program today

A unified platform that uses environment-aware context to prioritize risks saves

Get a Demo
Frame 2085669014
Group 1261154229