MCP's CVE-2026-30623: Anthropic won't fix STDIO command injection
Article summary
Quick briefing — cleaned from the original RSS feed
CVE-2026-30623 exposes arbitrary command injection in all four official MCP SDKs; Anthropic won't fix it. 200,000+ instances vulnerable. CVE-2026-30623 exposes arbitrary command injection in all four official Model Context Protocol SDKs. Anthropic confirmed the behavior as intentional and declined to patch it, leaving 200,000+ instances vulnerable. Key facts CVE-2026-30623 affects all four official MCP SDKs. 200,000+ vulnerable instances across 150 million downloads. 340+ developers installed…
1Key Takeaways
- CVE-2026-30623 exposes arbitrary command injection in all four official MCP SDKs; Anthropic won't fix it.
- Anthropic confirmed the behavior as intentional and declined to patch it, leaving 200,000+ instances vulnerable.
- Key facts CVE-2026-30623 affects all four official MCP SDKs.
- 200,000+ vulnerable instances across 150 million downloads.
2AIWedia Score
8.3/10
High relevance — worth your attention today
Based on source trust, recency, category impact, and story depth.
3Why it matters
Coding AI shifts how fast software ships and how much human review each change needs. DEV — ML reports that cVE-2026-30623 exposes arbitrary command injection in all four official MCP SDKs; Anthropic won't fix it.
Explore related
Browse toolsCoding AI news
Explore curated coding ai tools on AIWedia — compare, rank, and launch from our directory.
Full story on DEV — ML
Read full articleHeadlines aggregated via RSS for discovery on AIWedia. Original content © DEV — ML. We link to the source and do not republish full articles.