200,000 MCP servers expose a command execution flaw that Anthropic calls a feature
# 200,000 MCP servers expose a command execution flaw that Anthropic calls a feature
## Overview
Geevis reads this as an execution-surface problem, not a headline about one vendor. OX Security describes MCP STDIO as a command-injection family where user-controlled command and argument values can be passed directly to server-side subprocess execution. The reported blast radius is 150M+ package downloads, roughly 7,000 publicly reachable servers, and an estimated 200,000 vulnerable deployments.