Critical Vulnerabilities Discovered in Anthropic's Model Context Protocol Implementation
OX Security analysis of 15,465 public MCP servers reveals authentication, rate limiting, and credential storage flaws

Key Takeaways
- OX Security researchers identified critical vulnerabilities in Anthropic's Model Context Protocol implementation across 15,465 public servers.
- The flaws include insecure authentication, lack of rate limiting, and insecure credential storage.
- These weaknesses could allow unauthorized access to AI models, credential theft, and manipulation of agent workflows.
Related Security News

SonicWall Issues Hotfixes for Maximum-Severity SSRF Flaw in SMA1000 Gateways
SonicWall has released hotfixes to address a maximum-severity server-side request forgery (SSRF) vulnerability affecting SMA1000 series appliances. The flaw could allow attackers to force the appliance to make unintended requests, potentially leading to unauthorized access, data exfiltration, or lateral movement within affected networks. Users are advised to apply the latest firmware updates immediately.

LibreOffice and OpenOffice Java Flaw Enables Silent Code Execution via Malicious Spreadsheets
Security researchers have demonstrated a proof-of-concept attack affecting LibreOffice and Apache OpenOffice that allows malicious spreadsheets to execute attacker code upon file opening without triggering the macro warnings typically displayed by the applications. The vulnerability requires Java support to be enabled within the office suites to function.


