The OX Security Research team has uncovered a systemic AI supply chain vulnerability in Anthropic’s Model Context Protocol (MCP) . This RCE-by-Design flaw is an architectural choice that creates a critical security risk for any organization building with AI agents.
Through 30+ responsible disclosures and 10+ High/Critical CVEs , OX Security has worked to patch the downstream impact. However, the root cause remains at the protocol level. This research is a call for AppSec leaders and AI vendors to prioritize Software Supply Chain Security and “ Secure by Design ” architecture.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
