A design choice in the MCP SDKs allows remote code execution across the AI supply chain.
Anthropic sees no issues - and says the tools are working as intended.