116
MCP 'design flaw' puts 200k servers at risk and Anthropic won't fix it
(www.theregister.com)
Welcome to the main community in programming.dev! Feel free to post anything relating to programming here!
Cross posting is strongly encouraged in the instance. If you feel your post or another person's post makes sense in another community cross post into it.
Hope you enjoy the instance!
Rules
Follow the wormhole through a path of communities !webdev@programming.dev
AI a security risk? Can't be! 🙄
It’s worse even than that. The server software (released by Anthropic) that lets an AI connect to a web service has a critical arbitrary remote code execution bug. So if you even let an AI connect to you, you’ve now allowed anyone to access your whole server.
There is no excuse for this other than wild incompetence.
Wait, but Mythos is the revolution in the software security world, it found 0-days in all popular OS's, including FreeBSD. I'm sure it would have found critical bugs in their own code! /s
Ai isn't a security risk, if you know how to use the tool. Just add the line "Make no mistake" to the prompt. Not even a "please" is needed.
Modern problems require modern solution.