MCP command execution flaw: what security teams need to know

TL;DR AI
2 min readKey summary
Researchers found that MCP’s default STDIO transport can execute received OS commands without sanitization, creating a path to arbitrary command execution.
OX Security confirmed the issue in multiple live products and reported vulnerable deployments across the MCP ecosystem.
Anthropic said the behavior is expected by design and that mitigation is up to developers, not the protocol itself.
The flaw affects a widely used AI-to-tool standard and could expose enterprise agents to remote command execution unless integrations are hardened.



