this issue is not even MCP at the core. Claude Code/ Gemini CLI were opening "url's" without sanitization and validation. That's the core flaw.
There is a second issue with an XSS flawed package too in the bridge that is easy to patch.
So there is a chain of issues and you need to leverage them to get there and first pick an MCP that is flawed from a bad actor.