If you've added an MCP server to a claude_desktop_config.json or an mcp.json file this year by copy-pasting a connection string, this one's for you. This isn't a "is MCP good or bad" post — it's a breakdown of exactly what broke at the protocol level in 2026, what's shipping in six days to fix part of it, and the specific checks worth adding to your own review process before the next server goes in.

On April 15, 2026, OX Security disclosed a flaw sitting inside every official Model Context Protocol SDK — Python, TypeScript, Java, Rust. All four. Anthropic confirmed the behavior was intentional. Then it declined to change it.

The flaw let anyone who could influence a server's configuration file run arbitrary shell commands on the host machine. OX Security counted more than 200,000 vulnerable instances sitting inside a supply chain of over 150 million downloads.

I connect new MCP servers most weeks. I never once asked whether the protocol itself, the wiring underneath every server I trust, shipped with a design decision nobody was willing to walk back. I do now.

Where MCP Sits On The Agent Stack