The Register Home Page

back to article Anthropic won't own MCP 'design flaw' putting 200K servers at risk, researchers say

A design flaw – or expected behavior based on a bad design choice, depending on who is telling the story – baked into Anthropic's official Model Context Protocol (MCP) puts as many as 200,000 servers at risk of complete takeover, according to security researchers. The Ox research team says they "repeatedly" asked Anthropic to …

  1. cyberdemon Silver badge
    Flame

    In other news

    https://www.theregister.com/2026/04/07/anthropic_all_your_zerodays_are_belong_to_us/

    Anthropic are setting themselves up as a cyber arms-dealer, just not in the way you thought

    Like the firefighter who moonlights as an arsonist

    1. Cubbie Roo

      Like the firefighter who moonlights as an arsonist

      Yup distinct mafia vibes; selling 'protection' against the very violence they are happily unleashing. Maybe that looked like the smart play in 2025, but when the money dries up you'll be denied passing Go, and heading straight to Jail.

    2. Anonymous Coward
      Anonymous Coward

      Re: In other news

      By not releasing Claude Mythos they're reventing developing defenses against it, and they're preventing software producers to fix the problems it brings.

      What it DOES do is make it possible to re-open the door with an espionage-addicted US government, and given that that club has just extended FISA I think the signs are pretty clear.

      Even Trump's dislike is no match against the US compulsion to spy on everything that moves.

      1. druck Silver badge

        Re: In other news

        Did you not clock the name they gave it?

        Just more AI hype to delay the bubble bursting.

    3. amanfromMars 1 Silver badge

      Re: In other news .... which I presume is supposed to have Anthropic quaking in their boots .....

      .... rather than laughing up their sleeves

      MI5 is racing to bolster the defences of Britain’s most critical companies against the hacking threat posed by a powerful new wave of AI… [eg Anthropic's Mythos and such like] ..... https://www.telegraph.co.uk/business/2026/04/19/labour-mi5-protect-national-infrastructure-from-ai-threat/

      FFS ...... really? You’re ‘avin’ a larf, mate, if you think Holywood Palace Barracks’s finest are fighting fit for the future and in any way be adequately enabled to contend with and influence the direction of geopolitical travel today in the Greater IntelAIgent Games Plays which all of your tomorrows so effortlessly bring.

  2. Arkitekt

    What a surprise that an AI company would be dirty... after all, they only want to bring sunshine and rainbows to the world.

  3. Pascal Monett Silver badge
    Trollface

    Bug or feature?

    It's the Intartubes. Everything is a feature.

    In other news, Anthropic is really starting to look like something to avoid at all costs.

    1. jake Silver badge

      Re: Bug or feature?

      Starting, sir?

      Starting?

      Are you sure that word means what you think it means?

    2. bombastic bob Silver badge
      FAIL

      Re: Bug or feature?

      Anthropic should know better than to have "vibe coded" the MCP

    3. Anonymous Coward
      Anonymous Coward

      Re: Bug or feature?

      Well, if you want to be able to give it more than 1 prompt per 6 hours, you must be greedy!

      https://old.reddit.com/r/claude/comments/1s2f6ic/hitting_claude_limit_after_1_message_what_is/

  4. T. F. M. Reader Silver badge

    It's intelligent, innit?

    I am not entirely sure about my understanding. Presumably, if I am a normal, unprivileged user on my Linux machine, I will only be able to start an STDIO server with my own privileges. So me running an arbitrary shell command or script does not create a new hole. Am I supposed to understand that my MCP/STDIO server will accept API requests from anyone at all (any local user and, if firewalls permit, any remote user anywhere) with arbitrary commands inside, and will run any such command before retirning any diagnostics? This is what the article and the linked blog seem to imply, but, as I said, it's so fscking weird that I am not entirely certain.

    If the above is right then it is more of an API access question (and yes, a command whitelist may also be useful, but may be restrictive, too).

    It seems that thinking in terms of "intent" rather than "capabilities" is viral in the AI world, and for security it is horribly enough to be absolutely terrifying. The preferred method to install stuff also seems to be "curl https://www.fubar.com/snafu.sh | sh". Do we need a natural intelligence test to allow creating and operating artificial intelligence tools?

    1. Dan 55 Silver badge

      Re: It's intelligent, innit?

      I skimmed the PDF. All I can conclude is that the local command execution feature does what it says on the tin and executes commands locally and shrug.

    2. MonkeyJuice Silver badge

      "curl https://www.fubar.com/snafu.sh | sh".

      You forgot sudo

      1. jake Silver badge

        Re: "curl https://www.fubar.com/snafu.sh | sh".

        He was probably assuming the idiots using this kind of advice are running as root.

        1. T. F. M. Reader Silver badge

          Re: "curl https://www.fubar.com/snafu.sh | sh".

          I didn't assume root. I did assume idiocy (as in "anyone who runs this as is is a certified idiot"). The command I quoted hides a link to one actual "download" page (of a very popular AI tool). There is no sudo in that particular case, all I omitted was some curl options (that may vary with your mileage).

          Actually, sudo may be counterproductive if the idiot in question is not a sudoer - there will be an error and the installation will fail (and the case will have to be dealt with, with an idiot on the other end of the line).

          Of course I understand some idiots will run it as root (and many will run everything as root). But even if not, if the shell script installs malware that only waits to exploit some privilege escalation now or in the future (idiots won't prevent downloading updates from C&C servers, I assume) the result will be equivalent. And even a regular user's creds may cause real damage.

          1. T. F. M. Reader Silver badge

            Re: "curl https://www.fubar.com/snafu.sh | sh".

            Mmm... Bad form in following up on my own post, but I've just missed the edit window and the most important point deserves to be reiterated.

            People who consider this method of installing their software acceptable cannot be trusted to create secure software in the first place.

    3. MrBill

      Re: It's intelligent, innit?

      I suspect the authors are thinking that the LLM may use the stdio interface to run arbitrary commands based on user prompts. This is just the result of giving the LLM access to a shell.

      If you were going to use this for anything beyond a local deployment you would have to sandbox the MCP server, presumably using Unix access controls. Even for a local interface you should sandbox the MCP server. Or you could just use the web service interface instead...

      I don't see any way to change the MCP protocol to fix this security problem, other than by removing the stdio interface. Perhaps the ox.security team is indulging in some marketing to get attention.

  5. David Austin

    Of COURSE it's the MCP

    Did TRON teach us nothing, or is this another "Do Not Create The Torment Nexus" situation?

    1. bombastic bob Silver badge
      Thumb Up

      Re: Of COURSE it's the MCP

      icon for obligatory TRON reference. Well done, I was looking for a place to do something similar. You win teh intarwebs!

    2. Guido Esperanto

      Re: Of COURSE it's the MCP

      Get this clown trained. I want him in the Games until he dies playing.

      Acknowledge.

    3. Anonymous Coward
      Anonymous Coward

      Re: Of COURSE it's the MCP

      Hey, the MCP created "MCP (Model-Controller-Presenter)". as a diversion.

      Who invented this new one?

    4. ITPerson

      Re: Of COURSE it's the MCP

      End of line

    5. An_Old_Dog Silver badge
      Windows

      Re: Of COURSE it's the MCP

      When I read, "MCP" in the headline, I thought, "Master Control Program" -- but from Burroughs' OS, rather than from Tron.

      1. jake Silver badge

        Re: Of COURSE it's the MCP

        Burroughs' offering has been continuously available for around 65 years[0]. Look up Clearpath/MCP ...

        One wonders if this modern thing called MCP will still be around in a couple years. Or months, for that matter.

        [0] Yes, MCP pre-dated Tron by a couple decades ...

  6. O'Reg Inalsin Silver badge

    Less a bug than ..

    a digital security culture equivalent of Sodom and Gomorrah, and orgy of loose digital security mores.

    The article doesn't mention the proposed fix - but assuming it's whitelist with wildcards most whitelists will end up with a single entry "*" anyway. Anything goes.

  7. remainer_01
    Go

    Shocking!

    I’m SHOCKED that moving fast and breaking things is, in fact, breaking things.

    Anyone that casts even a passing glance at the entire MCP nonsense should march in the opposite direction sharpish, this issue is just is of the more obvious flaws with this nonsense “protocol”

    LLMs are notoriously bad at instruction following, why give it access to anything you can’t afford to lose?

  8. Anonymous Coward
    Anonymous Coward

    aipidemic

    stdio and fixed api keys should be forbidden. two most insecure choices. How much of AI will still function is everything is required to use streaming https and oauth2.? not much. why they exist ? lazy security and easy desktop user implementation .if anything. MCP is insecure by design and far off for enterprise use. still half of the world uses it.. Many bugs exist in MCP and a lot in authentication. when you report bus, github auto closed issues because they might or not beare handled by the team in another hidden tracker. no transparancy and so the issie expires after 7 or 22 days even its a totally valid bug .. M2M client credentials and device authentication oauth2 protocols are not even considered or implemented in hosts. how tokens and keys are securley stored is a big question. MCP sucks in security. it an open playground for hacker if your desktop or server gets compromised..

  9. Roo
    Windows

    The predictable yet glorius irony ...

    I spend a significant fraction of my day reviewing reports of vulnerabilities generated by "AI" and lesser tools. Stuff like command line arguments passed into main permitting "injection" attacks etc, and yet here we have one of those very tools with it's pants down around it's ankles taking up the rear from anyone who can open a connection. Bravo.

    AI companies eating their own dog food has predictably refined the process down to eating their own dog shit.

    1. amanfromMars 1 Silver badge

      Re: The predictable yet glorius irony ...

      I spend a significant fraction of my day reviewing reports of vulnerabilities generated by "AI" and lesser tools. Stuff like command line arguments passed into main permitting "injection" attacks etc, and yet here we have one of those very tools with it's pants down around it's ankles taking up the rear from anyone who can open a connection. Bravo.

      AI companies eating their own dog food has predictably refined the process down to eating their own dog shit. ...... Roo

      Roo, Hi.

      Your post avoided any comment on whether the development was a viable invisible and intangible existential threat to the continued predominant responses/reactions/self-destructive leaderships by an historical a priori few, skulking and exercising puppet and muppet strings in the dark shade and dodgy shadows of Earth’s rotten and crumbling inglorious and ignominious geopolitical landscapes with populated stages for mass mainstream media studio manipulation ........ without which they rapidly fade away and forever die.

      Would/Does the likes of an Anthropic MCP STDIO Server deliver them or save them from that fate with such as would certainly be lines of strings of alien correction? More than just strange and curious minds would surely give many fortunes to know in order to ensure a right positive outcome/a definitive constructive answer to the prayers of billions/a final solution to abiding unnecessary problems ?????

      And now that it has been mooted, will it be suicidal and not just both evil and foolish to try to hinder and stop further developments exploring the benefits and rewards to be associated with and responsible for Functional Gains of Superior Singularities of Greater Future Purpose?

      And [would it] it would be wise to realise all the above are rhetorical questions and faits accomplis ‽ .

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon