Researchers at OX Security disclosed an architectural flaw in Anthropic’s Model Context Protocol (MCP) SDKs across Python, TypeScript, Java, and Rust: an unsafe default in the STDIO transport passes attacker-supplied configuration directly to the host operating system’s shell without sanitization. The flaw propagated into more than 7,000 public MCP servers and packages with a combined 150 million-plus downloads, including popular projects like LiteLLM, LangChain, and Flowise, letting an attacker execute arbitrary commands and reach API keys, internal databases, and chat histories. Several downstream projects had shipped patches by the time of disclosure, but many implementations remained vulnerable.