security
Apr 24, 2026
By Teun
MCP remote code execution flaw disclosed - Anthropic says works as designed
Security researchers disclosed that MCP's StdioServerParameters allow arbitrary command execution on servers, as commands and arguments passed to create local instances are executed in a server-side shell without input sanitization. Anthropic responded that there is no design flaw and that developers are responsible for input sanitization.
Security researchers at OX Security published a detailed analysis showing that MCP's StdioServerParameters allow arbitrary command execution on remote servers. The flaw affects all MCP implementations regardless of programming language, because the issue is in the protocol design rather than any specific implementation.
The issue is straightforward: when a client connects to an MCP server using the stdio transport, it sends parameters that include a command and arguments. These are executed in a server-side shell to create a new local server instance. There is no input sanitization requirement in the protocol specification, and the reference implementations do not include sanitization either.
This means an attacker who can send connection requests to an MCP server can include arbitrary commands in the parameters. Those commands execute with whatever privileges the MCP server process has. The result is remote code execution (RCE), the most severe category of security vulnerability. If the server runs as root or with broad filesystem access, the attacker gains the same access.
The researchers contacted Anthropic, who responded that there is no design flaw and that input sanitization is the developer's responsibility. This response drew criticism from the security community because Anthropic provides reference implementations that do not include sanitization, and many developers building MCP servers follow those examples without adding their own security layer. The response shifts the burden entirely to developers who may not have security expertise.
The practical impact is significant. As of April 2026, there are over 10,000 published MCP servers, and earlier research showed that 63% of publicly exposed OpenClaw instances run without any authentication. For those exposed instances running MCP servers over stdio transport, this vulnerability is remotely exploitable with no credentials required.
The mitigation is to never expose MCP servers directly to untrusted networks. Use authentication layers, network isolation, and input validation on all parameters before they reach the stdio transport. If you run a proxy in front of your MCP servers, make sure the proxy validates or strips StdioServerParameters before forwarding them.
This disclosure follows a pattern from April 2026 where AI agent infrastructure security received increasing scrutiny. The combination of rapid adoption, insufficient security defaults, and a growing attack surface means that operators need to treat their agent infrastructure with the same security rigor they would apply to any internet-facing service.