A design flaw – or expected behavior based on a bad design choice, depending on who is telling the story – baked into Anthropic's official Model Context Protocol (MCP) puts as many as 200,000 servers at risk of complete takeover, according to security researchers. The Ox research team says they "repeatedly" asked Anthropic to patch the root issue, and were repeatedly told the protocol works just fine, thank you, despite 10 (so far) high- and critical-severity CVEs issued for individual open source tools and AI agents that use MCP. A root patch, according to Ox, could have reduced risk across software packages totaling more than 150 million downloads and protected millions of downstream users. Anthropic "declined to modify the protocol's architecture, citing the behavior as 'expected,'" Ox researchers Moshe Siman Tov Bustan, Mustafa Naamnih, Nir Zadok, and Roni Bar said in a blog about their research, which began in November 2025 and included more than 30 responsible disclosure processes. A week after their initial report to Anthropic, the AI vendor quietly released an updated security policy – as seems to be the pattern when faced with AI bugs. The updated guidance says MCP adapters, specifically STDIO ones, should be used with caution, the team wrote in a subsequent 30-page paper [PDF]. "This change didn't fix anything," they added. Anthropic did not respond to The Register's inquiries for this story. According to the security sleuths, the root issue lies in MCP, an open sou...
MCP 'design flaw' puts 200k servers at risk: Researcher
The Register
·Jessica Lyons
·Published Apr 16, 2026
·Updated
Affected Software
2 affected components
Anthropic Model Context Protocol
IBM Langflow
Frequently Asked Questions
1
What is the main security concern highlighted in the article?
The article discusses a design flaw in Anthropic's Model Context Protocol (MCP) that puts 200,000 servers at risk of complete takeover.
2
Which software products are affected by the security vulnerability?
The affected products include Anthropic's Model Context Protocol and IBM Langflow.
3
What is the potential impact of the MCP design flaw?
The potential impact of the flaw is the complete takeover of numerous servers, posing a significant security risk.
4
Who identified the design flaw in the MCP?
The design flaw was identified by a team of security researchers known as the Ox research team.
5
When was the vulnerability listed as exploited?
The vulnerability was listed as exploited on April 16, 2026.