MCP flaw exposes 200,000 servers
- OX Security found a stdio transport flaw in the Model Context Protocol that can let malicious input execute commands on agent hosts without user interaction. - The audit says roughly 200,000 MCP-linked agent servers could be exposed, and named Windsurf, Cursor, Claude Code and Gemini CLI as related attack surfaces. - The finding argues you must treat MCP servers, registries and tool adapters as privileged infrastructure, not convenience plugins. (venturebeat.com)