TopVuln

High-risk vulnerability digests

CVE-2025-49596

  • CRITICAL

Anthropic MCP Design Vulnerability Enables RCE, Threatening AI Supply Chain

Details

CVSS v3
9.9
EPSS
2.9% probability · 86.4th percentile — 2026-05-12
Affected versions
Anthropic MCP SDK (Python, TypeScript, Java, Rust), dependent projects: LiteLLM, LangChain, LangFlow, Flowise
Summary
This critical by-design vulnerability exists in the Anthropic Model Context Protocol (MCP) SDK due to unsafe default configurations over the STDIO transport interface. It allows remote attackers to achieve arbitrary remote code execution on systems running vulnerable MCP implementations. Successful exploitation grants attackers access to sensitive data including API keys, database credentials, and chat histories, posing broad AI supply chain risk. The flaw affects over 7,000 public servers and packages with over 150 million total downloads.
Remediation
Update to the latest patched versions of the Anthropic MCP SDK and all dependent MCP projects immediately. Restrict network access to MCP servers to only trusted sources and disable STDIO transport if it is not actively required. Review configuration settings and monitor for unusual access to sensitive AI system data.
Exploit info
No public exploit found yet.

View on NVD

TopVuln sends digest emails with high-risk CVE picks across multiple authoritative sources—curated with EPSS and AI. Choose daily per-stream emails and optional weekly or monthly roundups.

Subscribe — free email digest or paid plan

Information is aggregated from multiple authoritative sources for convenience; verify with NVD and vendors before operational decisions.