Breaking News: Shai-Hulud Outbreak Debrief: The Worm Evolves into MCP
Read the Report
OX Security is recognized as a Leader in the 2026 Gartner® Magic Quadrant™
Read the full report
OX Security Named a Sample Vendor Across 3 Categories in the Gartner® Hype Cycle™ for Application Security
Read More

The MCP Supply Chain Risk: Insights for Security Leaders

The Mother of All AI Supply Chains, insights on Anthropic’s “by design” failure at the heart of the AI ecosystem.
The MCP Supply Chain Risk Insights for Security Leaders (1)

Get the Cheat Sheet

Key findings:

A systemic flaw at the core of MCP.

A design choice in the Model Context Protocol’s STDIO handling enabled unauthenticated command injection and full takeover.

The risk moved downstream, silently.

Anthropic, LangChain, and FastMCP all responded “by design.” The risk didn’t disappear, it shifted to users.

AI-era shadow IT is invisible and highly privileged.

9 of 11 MCP marketplaces accepted a malicious server with no review; only GitHub’s managed registry blocked it.

Unified platform context.

MCP servers access source code, API keys, databases, and private conversations, often outside any inventory.

If you don’t know which MCP-enabling tools are running in your developer environment right now, this report is for you.

OX Security research coordinated 30+ disclosures across the MCP ecosystem, uncovering 10+ CVEs and 200+ affected open-source projects. The core issue is a critical, systemic vulnerability at the heart of MCP, and vendor responses of “by design” mean the exposure is now a downstream problem for the organizations that adopted these tools.

Inside the report: 6 insights and what to do

  • Responsibility tends to shift. When vendors respond “by design,” risk moves downstream silently. Build a process for surfacing unresolved upstream vulnerabilities.
  • Open source is accumulating unpaid security debt. 9 of 11 marketplaces accepted a malicious server; many maintainers didn’t respond for weeks. Prefer commercially-backed dependencies; flag OSS critical-issue response over 30 days as high-risk.
  • Not all marketplaces are equal. Only GitHub’s managed registry blocked the malicious submission. Maintain an approved registry list; block unapproved sources.
  • IDE security posture varies widely. Windsurf allowed zero-click RCE; Copilot showed an explicit warning. Audit IDEs in use; standardize on tools that warn on MCP config changes.
  • AI tool adoption requires dedicated governance. LangFlow, GPT Researcher, and LettaAI all exposed STDIO with no sanitization. Establish an AI integration intake process; flag STDIO as high-risk.
  • AI-era shadow IT is invisible and highly privileged. MCP servers reach source code, keys, databases, and private conversations. Scan for processes communicating over STDIO or known MCP ports.

By the numbers:

150M+ downloads exposed.

200K+ exposed servers.

10+ CVEs and counting.

30+ coordinated disclosures • 200+ affected OSS projects • 11 marketplaces tested, 9 failed.

"The OX Security platform is a game changer for application security teams. It is easy to adopt and integrate into the CI/CD pipeline and provides us the visibility and focus we need to develop fast and secure."

Moshe Belostosky Director of Infrastructure at

"OX Security supports our need for transparency and end to end traceability, ensuring security throughout our processes. This provides us with greater control - blocking vulnerabilities and improving accuracy during the development lifecycle."

Danny Wishlitzky Head of IT and Cybersecurity, CISO, DPO, Proximity

OX is changing the software supply chain security game. It gives a complete and reliable snapshot of code security before deployment

Golan Barash CISO at 888 holdings

Change the trajectory of your entire security program today

A unified platform that uses environment-aware context to prioritize risks saves

Get a Demo
Frame 2085669014
Group 1261154229