MCP Ships 40+ CVEs Into a Protocol About to Lock Them In
The Model Context Protocol has a vulnerability problem that is not a bug—it is a consequence of deliberate architectural choices. Across MCP’s four official SDKs, more than 40 CVEs have been catalogued since the protocol’s launch, affecting the TypeScript, Python, Go, and Java implementations. These are not implementation errors that slipped through testing. They are…