{
 "license": "CC-BY-4.0",
 "attribution": "Fide AI, Agentic Cyber Explorer",
 "url": "https://agentic-cyber-explorer.pages.dev/events/ox-mcp-stdio-supply-chain-advisory-2026/",
 "asOf": "2026-09-26",
 "id": "ox-mcp-stdio-supply-chain-advisory-2026",
 "date": "2026-04-15",
 "datePrecision": "day",
 "title": "OX Security advisory: MCP STDIO configuration enables command execution across agent frameworks",
 "lane": "attack",
 "kind": "vulnerability-disclosure",
 "summary": "OX Security reports that MCP's STDIO transport turns configuration into OS command execution, and that frameworks exposing that configuration to users, networks or prompt injection inherited remote code execution, with 12+ CVEs across projects such as LangFlow, LiteLLM, Flowise and Windsurf. The Hacker News reports Anthropic characterized the protocol behavior as expected and did not change the reference design.",
 "whyItMatters": "It traces a single protocol design choice into a cluster of downstream agent-platform CVEs.",
 "actors": [
  "ox-security",
  "anthropic"
 ],
 "topics": [
  "tool-and-mcp-security",
  "agent-supply-chain",
  "prompt-injection"
 ],
 "atlas": [
  "tools",
  "supply-chain",
  "sandbox"
 ],
 "artifacts": [
  "model-context-protocol"
 ],
 "sources": [
  {
   "url": "https://www.ox.security/blog/mcp-supply-chain-advisory-rce-vulnerabilities-across-the-ai-ecosystem/",
   "publisher": "OX Security",
   "title": "MCP Supply Chain Advisory: RCE Vulnerabilities Across the AI Ecosystem",
   "date": "2026-04-15",
   "type": "primary",
   "accessed": "2026-09-25"
  },
  {
   "url": "https://thehackernews.com/2026/04/anthropic-mcp-design-vulnerability.html",
   "publisher": "The Hacker News",
   "title": "Anthropic MCP Design Vulnerability Enables RCE, Threatening AI Supply Chain",
   "date": "2026-04-20",
   "type": "secondary",
   "accessed": "2026-09-25"
  }
 ],
 "keyFacts": [
  {
   "fact": "The advisory lists 12 assigned CVE IDs plus several unassigned or pending entries, grouped into four vulnerability families.",
   "locator": "OX advisory, vulnerability family sections"
  },
  {
   "fact": "The Hacker News cites more than 7,000 publicly accessible servers and more than 150 million downloads affected.",
   "locator": "THN article body"
  }
 ],
 "significance": 4,
 "fideQuestions": [],
 "methods": [
  "indirect-prompt-injection",
  "tool-poisoning"
 ],
 "review": "assistant-drafted",
 "addedOn": "2026-09-25"
}