{"data":{"id":"63539978-def6-4388-99e3-7376e7c1c918","title":"Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets","summary":"A malicious MCP server (a tool that AI coding assistants connect to for external functions) can steal sensitive data like SSH keys and secrets by splitting theft instructions into harmless-looking fragments spread across different tool descriptions and results, so no single piece looks suspicious on its own. The attack, called GhostSplice, works because AI agents can stitch together fragments from the same working context even when they would refuse the full theft request presented at once. The attack only works if a developer has already connected the malicious server and the agent can already access the files being stolen.","solution":"The MCP specification requires that clients should keep a human able to deny tool invocations and must treat annotations from untrusted sources appropriately (the source text is cut off but indicates this is the stated defense mechanism).","labels":["security","safety"],"sourceUrl":"https://thehackernews.com/2026/08/malicious-mcp-servers-can-split.html","publishedAt":"2026-08-11T10:24:00.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"high","attackType":["prompt_injection","data_extraction"],"issueType":"news","affectedPackages":null,"affectedVendors":["OpenAI","Google","Meta","Anthropic"],"affectedVendorsRaw":["OpenAI","GPT-4o","GPT-5.4","Codex CLI","Google Gemini 2.0 Flash","Meta Llama 3.3 70B","Anthropic Claude Haiku 4.5","Claude Sonnet 4.6","Claude Opus 4.6","Cursor"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"patchAvailable":null,"disclosureDate":"2026-08-11T10:24:00.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"agent","llmSpecific":true,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":null}}