
"Works as designed" isn't the same as "safe by default." CVE-2026-22252 hit 7,000+ MCP servers across Python, TypeScript, Java, and Rust — Anthropic confirmed input sanitization is the developer's job. That gap is exactly where RCE lives. 🚨 https://t.co/oCwxvSe5oL
Post summary
The tweet announces the existence and scope of CVE‑2026‑22252, highlighting a remote code execution flaw across several programming languages, but does not provide a PoC, exploit, patch, or evidence of active exploitation.
