Chronicle/Attacks & incidents

OX Security advisory: MCP STDIO configuration enables command execution across agent frameworks

AttackVulnerability disclosureSignificance assistant-drafted

OX Security reports that MCP's STDIO transport turns configuration into OS command execution, and that frameworks exposing that configuration to users, networks or prompt injection inherited remote code execution, with 12+ CVEs across projects such as LangFlow, LiteLLM, Flowise and Windsurf. The Hacker News reports Anthropic characterized the protocol behavior as expected and did not change the reference design.

Why it matters

It traces a single protocol design choice into a cluster of downstream agent-platform CVEs.

Key facts

As stated in the sources, with where to find them.

  • The advisory lists 12 assigned CVE IDs plus several unassigned or pending entries, grouped into four vulnerability families.OX advisory, vulnerability family sections
  • The Hacker News cites more than 7,000 publicly accessible servers and more than 150 million downloads affected.THN article body

Findings that cite this record

Key questions this bears on

Sources

Related records