# By Design

Canonical: https://brew.new/browse/templates/email/pt1_k97ysjthgy4he55xncr16y0jr98e4nas

Brand: ox.security
Category: newsletter

![Preview of By Design](https://cdn.brew.new/email-preview-2e9f81492b6b10f6-tracking_r57qskcq4bx215hk3t57swd8h18dtstq-1789009635547.png)

## Email content

Critical, Systemic Vulnerability at the Core of the MCP (1)

Hey there

The OX Security Research team has uncovered a systemic AI supply chain vulnerability in Anthropic’s MCP.

This "RCE-by-Design" flaw is an architectural choice that creates a critical security risk for any organization building with AI agents, exposing 150M+ downloads and 200K servers to complete takeover.

Read Now

Report Findings:

Systemic Exposure: 150M+ downloads across Python, TypeScript, Java, and Rust SDKs.

Impact: Remote Command Execution (RCE) which exposes unauthorized access to sensitive data and API keys.

Vulnerable Frameworks: Impacting industry staples like LangChain, LiteLLM, and IBM's LangFlow.

Verified Vectors: Zero-Click Prompt Injection in Windsurf, and One & Two-Click Prompt Injection in Cursor, Claude Code, Gemini-CLI.

It is time to prioritize "Secure by Design" architecture across the entire AI ecosystem.

P.S. We will be breaking this research down on Thursday, April 23rd during a live session. Watch your inbox for more details 👀.

- Team OX

LinkedIn

X

Instagram

YouTube

OX Security, 488 Madison Ave., New York, New York 10022, USA

Manage preferences

[Open and remix this design](https://brew.new/browse/templates/email/pt1_k97ysjthgy4he55xncr16y0jr98e4nas)

[Browse email designs](https://brew.new/browse/templates)
