A design choice in the MCP SDKs allows remote code execution across the AI supply chain.
Wiz discovered a critical remote code execution vulnerability in GitHub that exposed millions of repositories.