OX Security reports that MCP's STDIO transport turns configuration into OS command execution, and that frameworks exposing that configuration to users, networks or prompt injection inherited remote code execution, with 12+ CVEs across projects such as LangFlow, LiteLLM, Flowise and Windsurf. The Hacker News reports Anthropic characterized the protocol behavior as expected and did not change the reference design.
Why it matters
It traces a single protocol design choice into a cluster of downstream agent-platform CVEs.
Key facts
As stated in the sources, with where to find them.
- The advisory lists 12 assigned CVE IDs plus several unassigned or pending entries, grouped into four vulnerability families.OX advisory, vulnerability family sections
- The Hacker News cites more than 7,000 publicly accessible servers and more than 150 million downloads affected.THN article body
Findings that cite this record
Key questions this bears on
- Can prompt injection against AI agents be reliably defended?Not reliably. Defenses reduce injection but none has eliminated it; limiting what untrusted input can trigger is the most defensible approach.
- Where are deployed AI agents actually being exploited?Mostly around the model: connectors, credentials, tools, and packages, rather than the model alone.
Sources
Related records
Apr 1, 2025
Feb 25, 2026
Jan 20, 2026
Aug 19, 2025
Mar 30, 2025
May 7, 2026