Security & Supply ChainMCP STDIO risk: when config becomes command execution
OX Security argues MCP STDIO can turn configuration into OS command execution when command and args are untrusted. Here is the exploit map and a hardening checklist for frameworks, IDEs, and platforms.