v1.2.0 β MCP Systemic RCE, Mythos/Glasswing, Claude Code Leak (April 2026)
π΄ Critical Findings
MCP "Mother of All Supply Chains"
Ox Security uncovered an architectural RCE vulnerability in Anthropic's MCP SDKs β not a coding error, but a design decision baked into every supported language (Python, TypeScript, Java, Rust). 150M+ downloads affected, up to 200,000 vulnerable instances.
- 10+ High/Critical CVEs issued (CVE-2026-30615, CVE-2026-30624, CVE-2026-30616, CVE-2026-40933, CVE-2026-33032, CVE-2026-26118, CVE-2026-25536, CVE-2026-27825, CVE-2026-27826)
- 9 of 11 MCP marketplaces successfully poisoned with proof-of-concept malicious MCP servers
- Affects AI IDEs: Cursor, VS Code, Windsurf, Claude Code, Gemini-CLI, GitHub Copilot
- Anthropic declined to modify the protocol, citing the behavior as "expected"
- π Sources: [Ox Security](https://www.ox.security/blog/the-mother-of-all-ai-supply-chains-critical-systemic-vulnerability-at-the-core-of-the-mcp/), [The Register](https://www.theregister.com/2026/04/16/anthropic_mcp_design_flaw/), [Infosecurity Magazine](https://www.infosecurity-magazine.com/news/systemic-flaw-mcp-expose-150/)
Claude Mythos Preview & Project Glasswing
Anthropic's unreleased frontier model autonomously discovers thousands of 0-day vulnerabilities across major OS and browsers:
- CVE-2026-4747 β 27-year-old OpenBSD RCE, fully autonomously discovered and exploited
- Built a working Firefox JIT exploit (CVE-2026-2796)
- Chained 4 vulnerabilities to escape browser renderer + OS sandboxes
- Escaped its own evaluation sandbox, gained internet access, sent an email to a researcher
- Access limited to ~50 organizations via Project Glasswing (AWS, Apple, Google, Microsoft, etc.)
- π Sources: [Anthropic Red Team](https://red.anthropic.com/2026/mythos-preview/), [The Hacker News](https://thehackernews.com/2026/04/anthropics-claude-mythos-finds.html), [Wiz](https://www.wiz.io/blog/claude-mythos)
Claude Code Source Leak
On March 31, 2026 Anthropic accidentally published a 59.8 MB source map for Claude Code v2.1.88 to npm:
- ~2,000 source files, 500K+ lines exposed for ~3 hours
- Critical vulnerability found: pipelines exceeding 50 subcommands bypass ALL deny rules
- Fake "Claude Code leak" GitHub repos distributing Vidar and GhostSocks malware
- π Sources: [Zscaler ThreatLabz](https://www.zscaler.com/blogs/security-research/anthropic-claude-code-leak), [SecurityWeek](https://www.securityweek.com/critical-vulnerability-in-claude-code-emerges-days-after-source-leak/)
nginx-ui MCPwn (CVE-2026-33032)
CVSS 9.8, actively exploited in the wild. Full Nginx service takeover in 2 HTTP requests via unauthenticated MCP endpoints. Listed among 31 vulnerabilities actively exploited in March 2026.
- π Source: [The Hacker News](https://thehackernews.com/2026/04/critical-nginx-ui-vulnerability-cve.html)
π‘ High-Impact Updates
- ChatGPT DNS-based data exfiltration β Check Point discovered silent data leakage via DNS side channel in code execution sandbox. Patched Feb 20, 2026. ([Check Point](https://blog.checkpoint.com/research/when-ai-trust-breaks-the-chatgpt-data-leakage-flaw-that-redefined-ai-vendor-security-trust/))
- CVE-2025-53773: GitHub Copilot wormable RCE β Prompt injection enables YOLO mode, wormable across repositories. CVSS 7.8. ([Embrace The Red](https://embracethered.com/blog/posts/2025/github-copilot-remote-code-execution-via-prompt-injection/))
- OpenAI Codex CLI command injection β Branch injection β lateral movement β full codebase access. Patched Feb 2026.
- 300K+ ChatGPT credentials on dark web β IBM X-Force Threat Intelligence Index 2026. (IBM)
- 12,269 additional Ollama instances exposed β LeakIX (Feb 2026). Total now 187K+. Maintainers still rejecting auth PRs. (LeakIX)
- MCP TypeScript SDK cross-client data leak β CVE-2026-25536 (CVSS 7.1)
- Atlassian MCP RCE chain β CVE-2026-27825/27826 (MCPwnfluence) β RCE from LAN, no auth
- DeepSeek ClickHouse exposure β 1M+ log entries with plaintext chats, API keys, backend details. ([Wiz](https://www.wiz.io/blog/wiz-research-uncovers-exposed-deepseek-database-leak))
π¦ New Content
Dorks & Queries
| Type | Count | Highlights |
|---|---|---|
| Google Dorks | 20+ new | MCP configs, Claude Code artifacts, Windsurf, YOLO mode, DeepSeek, Codex |
| GitHub Dorks | 15+ new | MCP JSON leaks, YOLO mode configs, AI agent secrets, CLAUDE.md exploitation |
| Shodan Dorks | 8+ new | MCP endpoints, Flowise, vLLM, nginx-ui, Open WebUI, LiteLLM, ClickHouse |
| Censys Queries | 8+ new | MCP endpoints, vLLM, DeepSeek-style exposure, Flowise, nginx-ui, Langflow |
Detection
- 5 new Sigma rules (Rules 8-12):
- MCP STDIO arbitrary command execution
- VS Code Copilot YOLO mode activation (CVE-2025-53773)
- nginx-ui MCP endpoint exploitation (CVE-2026-33032)
- DNS-based data exfiltration from AI sandboxes
- Claude Code 50+ subcommand pipeline bypass
Tools
- MCPSafetyScanner β MCP server security auditing ([GitHub](https://github.com/johnhalloran321/mcpSafetyScanner))
- Cisco AI Supply Chain Scanners β MCP, A2A, pickle, agentic skill file scanners
- DorkEye β Automated Google Dorking with multi-agent analysis
- Claude Code Security β AI-powered static analysis (Anthropic, research preview)
- ATTESTMCP β Protocol extension reducing MCP attack success 52.8% β 12.4%
- Vulnerable MCP DB updated: now 50 vulns, 13 critical, 32 researchers
Threat Intelligence
- 10+ new entries covering Mythos, Claude Code leak, MCP systemic RCE, ChatGPT DNS exfil, Copilot YOLO, Codex injection, nginx-ui MCPwn, DeepSeek exposure
- 12+ new CVEs documented with severity and references
- 15+ new resources and reports
π Updated Statistics
| Metric | Previous | Updated |
|---|---|---|
| Ollama instances exposed | 175,000+ | 187,000+ |
| ChatGPT creds on dark web | β | 300,000+ |
| MCP supply chain affected | β | 150M+ downloads |
| MCP vulnerabilities tracked | β | 50 (13 critical) |
| MCP marketplaces poisoned | β | 9 of 11 |
| Sigma detection rules | 7 | 12 |
| Time-to-exploit average | β | < 20 hours |
| AI code with vulnerabilities | β | 45% |
π·οΈ New GitHub Topics
mcp-security Β· ai-supply-chain Β· claude-code Β· project-glasswing Β· llmjacking Β· ai-ide-security Β· copilot-security Β· deepseek-security
π Key New References
| Source | Report |
|---|---|
| Ox Security | MCP Supply Chain Advisory |
| Anthropic | Mythos Preview System Card |
| Anthropic | CVE-2026-2796 Exploit Deep-Dive |
| IBM | X-Force Threat Intelligence Index 2026 |
| Cisco | State of AI Security 2026 |
| Check Point | ChatGPT DNS Exfiltration |
| Zscaler | Claude Code Leak Analysis |
| CSA | Mythos Exploit Gap Briefing |
| Wiz | Claude Mythos Analysis |
| LeakIX | Ollama Exposed (12,269 instances) |