Home
Major architectural flaws found in Anthropic MCP protocol, dozens of critical vulnerabilities alarm AI security community

The Model Context Protocol (MCP), an industry-standard communication protocol developed by AI company Anthropic, has recently faced serious security scrutiny. A research team called OX Security released a report revealing fundamental architectural flaws that could trick servers into executing arbitrary code (RCE). So far, 10 CVE identifiers have been linked to this issue, and the number continues to grow.
As an open protocol designed to standardize communication between AI models and external data sources, MCP was previously adopted by major companies like Microsoft and Google. However, on April 15, OX Security discovered that the vulnerability wasn't a simple coding oversight but was deeply embedded in the official SDK. This means MCP projects built using Python, TypeScript, Java, or Rust are all vulnerable and exposed to risk.
Through testing, researchers identified four mainstream attack vectors: unauthenticated UI injection, security hardening bypass, prompt injection, and malicious plugin distribution. Several major open-source projects, including LiteLLM, LangChain, and IBM LangFlow, have been confirmed to contain critical vulnerabilities and have been successfully exploited in real production environments. This discovery has effectively dropped a bombshell in the rapidly evolving AI infrastructure space.
Anthropic's response to the research team's findings has sparked widespread industry discussion. The research team reportedly tried multiple times to communicate and urge the company to fix the architectural flaw, but Anthropic refused to modify the underlying architecture, stating that the behavior was "intended design." With the other party's consent, the team then decided to disclose the findings publicly to warn developers to take preventive measures.
In light of the current risks, security experts have issued urgent recommendations for users and developers: Do not expose large language models and related AI tools directly to the public internet. Treat all MCP input data as untrusted sources and strictly prevent prompt injection attacks. Additionally, any service built on MCP should run in a strict sandbox environment, with timely software updates and system permissions tightened as much as possible.
Related article
U.S. Stocks Hit Historic Milestone as AI and Aerospace Giants Prepare for Trillion-Dollar Debut
Elon Musk, Sam Altman, and Dario Amodei, three titans of the technology sector, are advancing toward initial public offerings for their respective ventures. With SpaceX, OpenAI, and Anthropic—three industry behemoths nearing trillion-dollar valuation
Swedish AI Startup Lovable Eyes $13.2 Billion Valuation After Major Funding Round
As AI-driven coding tools gain traction, Swedish startup Lovable has secured a major funding round. The company aims to raise $3 billion, potentially boosting its valuation to $13.2 billion—double the $6.6 billion recorded last December. Menlo Ventur
Google Tests Remy AI Agent for Gemini as Focus Shifts to User Control
According to Business Insider, Google is testing Remy, a new AI personal agent for Gemini. This tool aims to execute tasks on behalf of users, streamlining both professional workflows and daily routines.Currently, Remy is undergoing testing in an int
Related Special Topic Recommendations
Comments (0)
0/500

The Model Context Protocol (MCP), an industry-standard communication protocol developed by AI company Anthropic, has recently faced serious security scrutiny. A research team called OX Security released a report revealing fundamental architectural flaws that could trick servers into executing arbitrary code (RCE). So far, 10 CVE identifiers have been linked to this issue, and the number continues to grow.
As an open protocol designed to standardize communication between AI models and external data sources, MCP was previously adopted by major companies like Microsoft and Google. However, on April 15, OX Security discovered that the vulnerability wasn't a simple coding oversight but was deeply embedded in the official SDK. This means MCP projects built using Python, TypeScript, Java, or Rust are all vulnerable and exposed to risk.
Through testing, researchers identified four mainstream attack vectors: unauthenticated UI injection, security hardening bypass, prompt injection, and malicious plugin distribution. Several major open-source projects, including LiteLLM, LangChain, and IBM LangFlow, have been confirmed to contain critical vulnerabilities and have been successfully exploited in real production environments. This discovery has effectively dropped a bombshell in the rapidly evolving AI infrastructure space.
Anthropic's response to the research team's findings has sparked widespread industry discussion. The research team reportedly tried multiple times to communicate and urge the company to fix the architectural flaw, but Anthropic refused to modify the underlying architecture, stating that the behavior was "intended design." With the other party's consent, the team then decided to disclose the findings publicly to warn developers to take preventive measures.
In light of the current risks, security experts have issued urgent recommendations for users and developers: Do not expose large language models and related AI tools directly to the public internet. Treat all MCP input data as untrusted sources and strictly prevent prompt injection attacks. Additionally, any service built on MCP should run in a strict sandbox environment, with timely software updates and system permissions tightened as much as possible.
U.S. Stocks Hit Historic Milestone as AI and Aerospace Giants Prepare for Trillion-Dollar Debut
Elon Musk, Sam Altman, and Dario Amodei, three titans of the technology sector, are advancing toward initial public offerings for their respective ventures. With SpaceX, OpenAI, and Anthropic—three industry behemoths nearing trillion-dollar valuation
Swedish AI Startup Lovable Eyes $13.2 Billion Valuation After Major Funding Round
As AI-driven coding tools gain traction, Swedish startup Lovable has secured a major funding round. The company aims to raise $3 billion, potentially boosting its valuation to $13.2 billion—double the $6.6 billion recorded last December. Menlo Ventur











