Key findings:
A systemic flaw at the core of MCP.
A design choice in the Model Context Protocol’s STDIO handling enables unauthenticated command injection and complete server takeover.
Massive exposure.
50M+ downloads and 200K+ exposed servers are affected, with 10+ CVEs and counting.
Deeply embedded across the ecosystem.
The weakness reaches widely used MCP SDKs and tools, including FastMCP, Agno, Letta, LangFlow, and Flowise, and Windsurf allowed zero-click RCE.
Vendors called it “by design.”
Anthropic, LangChain, and FastMCP responses shifted the risk downstream to the organizations that adopted these tools.
If you don’t know which MCP-enabling tools are running in your developer environment, you can’t rule out this exposure.
OX Security research demonstrated how a single malicious MCP server configuration can execute arbitrary commands on a host. Because the underlying behavior was deemed “by design,” the burden of mitigation falls on the organizations that deployed these tools, often without any inventory of what is actually running.
Inside the report:
- How a malicious MCP server configuration triggers command execution on the host, the STDIO design flaw.
- The scope of exposure: 150M+ downloads, 200K+ servers, 10+ CVEs.
- Affected SDKs and tools: FastMCP, Agno, Letta, LangFlow, Flowise, Windsurf, and others.
- How IDE behavior differs: Windsurf allowed zero-click RCE, while Copilot showed an explicit warning.
- Coordinated disclosure across 30+ reports and 200+ open-source projects; 9 of 11 marketplaces failed to block a malicious server.
By the numbers:
150M+ downloads exposed.
200K+ exposed servers.
10+ CVEs and counting.
30+ coordinated disclosures • 200+ affected OSS projects • 9 of 11 marketplaces failed.


