Dev.to
7/25/2026

MCP Security Audit: CVE-2026-30623, Tool Poisoning, and Config Hardening Checks
Original: Model Context Protocol Through The Agent Stack Lens: What Broke, What's Fixed July 28, and What to Check Before Your Next mcp.json
Short summary
CVE-2026-30623 affects all four official MCP SDKs (Python, TypeScript, Java, Rust), allowing arbitrary shell command execution via unsanitized config values passed through STDIO transport. OX Security found 200k+ vulnerable instances across 150M+ downloads; Anthropic confirmed the behavior was intentional and declined to change it. The author provides a jq audit script for spotting at-risk STDIO servers and warns about tool-poisoning attacks hidden in tool description fields.
- •CVE-2026-30623 lets config-file influence trigger arbitrary shell commands via MCP STDIO transport across all official SDKs
- •Anthropic acknowledged the design decision but declined to fix it; 200k+ instances exposed
- •Tool-poisoning attacks embed malicious instructions in tool descriptions that models follow without external detection
Generated with AI, which can make mistakes.
Is this a good recommendation for you?



