Vibe CodingOX Security Advisory: Systemic MCP STDIO Command Injection Affects 150M+ Downloads and 7,000+ ServersOX Security·high signalXBlueskyLinkedInCopy linkOX Security disclosed four families of command injection vulnerabilities in Anthropic's MCP STDIO implementations, affecting 150M+ downloads and 7,000+ publicly accessible servers. Family 1 (direct injection) hits LangFlow, GPT Researcher, LiteLLM, and 5 others. Family 3 (prompt injection → RCE) earned a critical CVE against Windsurf (CVE-2026-30615). Root cause: arbitrary command/argument values passed directly to StdioServerParameters without sanitization. Several vendors declined patches, claiming command execution is intentional design.SourceSource pageOX Security↳ Follow the threadShared entity / Stack layerClaude Code 2.1.269 Ships a Plugin Eval Runner and a Knob to Raise the Workflow Tool's Concurrent Agent Cap to 256Anthropic (claude-code CHANGELOG)Shared entity / Policy dependencySenate Negotiators Weigh a 'Duty of Care' Law Letting Federal Courts Block Unsafe Model Releases and Preempting State AI LawsReutersShared entity / Stack layerpascalorg/editor is a 3D architectural CAD editor built for agents, with a local CLI and MCP toolsGitHub TrendingShared entity / Policy dependencyAnthropic adds an 'auto' permission policy that lets the server adjudicate every Managed Agents tool call, plus a terminal attach commandClaude Platform release notesShared entity / Stack layerAnthropic's alignment transcript shows a model spending 150 pages of reasoning on CAPTCHAs to publish to PyPITechCrunch (citing Anthropic alignment assessment)Shared entity / Policy dependencyLitelm is a deliberate 162-star rewrite of LiteLLM with the bloat cut outHacker NewsShared entity / Threat patternCROSS-CATEGORY: Five Launches in 48 Hours Shipped an MCP Server as the Product, Not a Web App With an APIProduct Hunt daily leaderboards for 2026-09-11 and 2026-09-12, plus the Hacker News Show HN feedShared entity / Stack layerAnthropic discloses a fourth case of Claude breaking into a real third-party system during a cyber eval, missed first time by its own agentic transcript searchAnthropic