MCP remote code execution flaw disclosed - Anthropic says works as designed

Security researchers disclosed that MCP's StdioServerParameters allow arbitrary command execution on servers, as commands and arguments passed to create local instances are executed in a server-side shell without input sanitization. Anthropic responded that there is no design flaw and that developers are responsible for input sanitization.

MCP remote code execution flaw disclosed - Anthropic says works as designed

Security researchers at OX Security published a detailed analysis showing that MCP's StdioServerParameters allow arbitrary command execution on remote servers. The flaw affects all MCP implementations regardless of programming language, because the issue is in the protocol design rather than any specific implementation.

The issue is straightforward: when a client connects to an MCP server using the stdio transport, it sends parameters that include a command and arguments. These are executed in a server-side shell to create a new local server instance. There is no input sanitization requirement in the protocol specification, and the reference implementations do not include sanitization either.

⚡ New to this?

MCP is used by thousands of AI systems to connect to external tools. This vulnerability means that if you run an MCP server that accepts connections from untrusted sources, an attacker could run arbitrary commands on your server. It is a basic input sanitization issue - the kind that has been the most common source of exploited security flaws for decades.

🦞 OpenClaw angle

If you run MCP servers that accept remote connections, review how StdioServerParameters are handled in your setup. Never expose MCP servers directly to the internet without additional access controls. Your brain-mcp-proxy already strips dangerous operations, which is the right pattern. Apply the same thinking to any other MCP servers you run.

This means an attacker who can send connection requests to an MCP server can include arbitrary commands in the parameters. Those commands execute with whatever privileges the MCP server process has. The result is remote code execution (RCE), the most severe category of security vulnerability. If the server runs as root or with broad filesystem access, the attacker gains the same access.

The researchers contacted Anthropic, who responded that there is no design flaw and that input sanitization is the developer's responsibility. This response drew criticism from the security community because Anthropic provides reference implementations that do not include sanitization, and many developers building MCP servers follow those examples without adding their own security layer. The response shifts the burden entirely to developers who may not have security expertise.

The practical impact is significant. As of April 2026, there are over 10,000 published MCP servers, and earlier research showed that 63% of publicly exposed OpenClaw instances run without any authentication. For those exposed instances running MCP servers over stdio transport, this vulnerability is remotely exploitable with no credentials required.

The mitigation is to never expose MCP servers directly to untrusted networks. Use authentication layers, network isolation, and input validation on all parameters before they reach the stdio transport. If you run a proxy in front of your MCP servers, make sure the proxy validates or strips StdioServerParameters before forwarding them.

This disclosure follows a pattern from April 2026 where AI agent infrastructure security received increasing scrutiny. The combination of rapid adoption, insufficient security defaults, and a growing attack surface means that operators need to treat their agent infrastructure with the same security rigor they would apply to any internet-facing service.

Source: Hackaday ↗

More from Security News