The Mother of All AI Supply Chains: Anthropic’s “By Design” failure at the heart of the AI ecosystem

How an Anthropic design choice exposed 150M+ downloads, and 200K servers to complete takeover
Critical, Systemic Vulnerability at the Core of the MCP (2)

Get the Report

The OX Security Research team has uncovered a systemic AI supply chain vulnerability in Anthropic’s Model Context Protocol (MCP). This RCE-by-Design flaw is an architectural choice that creates a critical security risk for any organization building with AI agents.

Critical Security Impact & Findings

Remote Code Execution (RCE)

Enables unauthorized access to sensitive user data, internal databases, and API keys.

Systemic Exposure

Affects 150M+ downloads across Python, TypeScript, Java, and Rust MCP SDKs.

Supply Chain Attack Vectors

Verified Zero-Click Prompt Injection in Cursor and Windsurf, plus “poisoned” MCP registries.

Vulnerable AI Frameworks

Impacting industry staples like LangChain, LiteLLM, and IBM’s LangFlow.

The Call for “Secure by Design” AI

Through 30+ responsible disclosures and 10+ High/Critical CVEs, OX Security has worked to patch the downstream impact. However, the root cause remains at the protocol level. This research is a call for AppSec leaders and AI vendors to prioritize Software Supply Chain Security and “Secure by Design” architecture.

"The OX Security platform is a game changer for application security teams. It is easy to adopt and integrate into the CI/CD pipeline and provides us the visibility and focus we need to develop fast and secure."

Moshe Belostosky Director of Infrastructure at

"OX Security supports our need for transparency and end to end traceability, ensuring security throughout our processes. This provides us with greater control - blocking vulnerabilities and improving accuracy during the development lifecycle."

Danny Wishlitzky Head of IT and Cybersecurity, CISO, DPO, Proximity

OX is changing the software supply chain security game. It gives a complete and reliable snapshot of code security before deployment

Golan Barash CISO at 888 holdings

Change the trajectory of your entire AppSec program today

A unified platform that uses environment-aware context to prioritize risks saves

Get a Demo