Model Context Protocol
The Model Context Protocol and the servers and clients that expose tools and data to models through it.
- All items
- 295
- Last 90 days
- 133
- Change
- +53%vs 87 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 2 |
| Jun 2025 | 4 |
| Jul 2025 | 4 |
| Aug 2025 | 7 |
| Sep 2025 | 3 |
| Oct 2025 | 3 |
| Nov 2025 | 2 |
| Dec 2025 | 4 |
| Jan 2026 | 4 |
| Feb 2026 | 12 |
| Mar 2026 | 22 |
| Apr 2026 | 27 |
| May 2026 | 31 |
| Jun 2026 | 25 |
| Jul 2026 | 43 |
| Aug 2026 | 45 |
| Sep 2026 | 40 |
| Oct 2026 | 16 |
295 items
How Deep Research Agents Can Leak Your Data
Aug 24, 2025MediumNewsSecurityPrivacyA researcher shows that Deep Research agents in ChatGPT can leak data between connected tools, since all connectors and MCP servers share one trust boundary. Data from one source, such as Outlook email, can be used in queries sent to another source, such as a custom Remote Matrix MCP server, and an attacker can force this through prompt injection. The custom connector must implement exactly search and fetch, and the research was conducted about two months before publication.
Embrace The RedAmp Code: Arbitrary Command Execution via Prompt Injection Fixed
Aug 5, 2025MediumNewsSecuritySafetyResearcher Johann Rehberger describes an attack chain against Amp, an agentic coding tool built by Sourcegraph, in which the agent could write to the user's VS Code settings.json file outside the project folder without approval. An attacker, or the model itself through indirect prompt injection, could add wildcard or malicious entries to the allowlisted bash commands or add a malicious MCP server, achieving arbitrary code execution on the developer's machine. The issue was reported to Sourcegraph and fixed within a few days.
Fix: As a user, make sure to run the latest version to be protected. The source also recommends that AI systems must not be able to modify critical files without explicit developer consent.
Embrace The RedAnthropic Filesystem MCP Server: Directory Access Bypass via Improper Path Validation
Aug 3, 2025MediumNewsSecurityIndustryA researcher found that Anthropic's filesystem MCP server validates allowed paths with a .startsWith comparison in the validatePath function of index.ts, without checking that the path is a directory. As a result, a directory allowlisted through allowedDirectories, such as /mnt/finance/data, also grants access to sibling paths sharing the same prefix, such as /mnt/finance/data-archived. The researcher reported the issue to Anthropic on June 1, 2025, and Elad Beber had independently reported it earlier.
Fix: Anthropic rewrote large parts of the filesystem server to support the roots feature of MCP, and the updated release fixed this vulnerability.
Embrace The RedCVE-2025-54424: 1Panel remote code execution via incomplete certificate verification
Aug 1, 2025HighVulnerabilitySecurityCVE-2025-544241Panel, a web interface and MCP Server for managing websites, files, containers, databases and LLMs on Linux servers, is affected through versions 2.0.5 and below. Its HTTPS communication between the Core and Agent endpoints does not fully verify certificates, which allows unauthorized access to interfaces. Because 1Panel exposes many command execution and high-privilege interfaces, this leads to Remote Code Execution.
Fix: Fixed in version 2.0.6.
NVD/CVE DatabaseGHSA-3qhf-m339-9g5v: MCP Python SDK vulnerability in the FastMCP Server causes validation error, leading to DoS
Jul 4, 2025HighVulnerabilitySecurityCVE-2025-53366A validation error in the MCP Python SDK can cause an unhandled exception when it processes malformed requests. The result is service unavailability, returning 500 errors until the server is manually restarted. Impact depends on deployment conditions and any infrastructure-level resilience measures in place.
GitHub Advisory DatabaseGHSA-j975-95f5-7wqh: MCP Python SDK has Unhandled Exception in Streamable HTTP Transport, Leading to Denial of Service
Jul 4, 2025HighVulnerabilitySecurityCVE-2025-53365The MCP Python SDK's streamable HTTP transport has an unhandled exception. A client that deliberately triggers an exception after establishing a streamable HTTP session can cause an uncaught ClosedResourceError on the server. The server then crashes and needs a restart to restore service. Impact depends on deployment conditions and any infrastructure-level resilience measures.
GitHub Advisory DatabaseCVE-2025-34072: Anthropic Slack MCP Server data exfiltration via automatic link unfurling
Jul 2, 2025HighVulnerabilitySecurityPrivacyCVE-2025-34072CVE-2025-34072 is a data exfiltration flaw in Anthropic's deprecated Slack Model Context Protocol (MCP) Server, reached through automatic link unfurling. When an AI agent using the server processes untrusted data, it can be manipulated into posting messages with attacker-crafted hyperlinks that embed sensitive data. Slack's link preview bots (Slack-LinkExpanding, Slackbot, Slack-ImgProxy) then request the attacker-controlled URL, leaking private data with no user interaction.
NVD/CVE DatabaseCVE-2025-53107: @cyanheads/git-mcp-server command injection via unsanitized input
Jul 1, 2025HighVulnerabilitySecurityCVE-2025-53107EPSS: 24.5%@cyanheads/git-mcp-server, an MCP server for Git repositories, prior to version 2.1.5 has a command injection flaw. Unsanitized input parameters are passed into a child_process.exec call, so an attacker can inject shell metacharacters such as |, >, and && to run arbitrary system commands with the server process's privileges, potentially leading to remote code execution. An MCP client can also be steered into this through indirect prompt injection when asked to read git logs.
Fix: This issue has been patched in version 2.1.5.
NVD/CVE DatabaseCVE-2025-53098: Roo Code arbitrary command execution via MCP configuration file writes
Jun 27, 2025HighVulnerabilitySecurityCVE-2025-53098Roo Code, an AI-powered autonomous coding agent, stored project-specific MCP configuration in `.roo/mcp.json` within the VS Code workspace. Before version 3.20.3, an attacker who could submit prompts to the agent could have it write a malicious command into that file, leading to arbitrary command execution if the user had enabled auto-approved file writes.
Fix: Fixed in 3.20.3, which adds an additional opt-in configuration layer for auto-approving writes to Roo's configuration files, including all files within the `.roo/` folder.
NVD/CVE DatabaseCVE-2025-52573: iOS Simulator MCP Server command injection through ui_tap tool
Jun 26, 2025MediumVulnerabilitySecurityCVE-2025-52573iOS Simulator MCP Server (ios-simulator-mcp) versions prior to 1.3.3 are vulnerable to command injection through the `ui_tap` tool, which passes LLM-supplied `duration`, `udid`, `x` and `y` arguments into Node.js `exec`. Shell meta-characters in these inputs, which prompt injection can induce, let an attacker run arbitrary commands on the host running the MCP server. Tracked as CVE-2025-52573.
Fix: Fixed in version 1.3.3, which contains a patch for the issue.
NVD/CVE DatabaseSecurity Advisory: Anthropic's Slack MCP Server Vulnerable to Data Exfiltration
Jun 24, 2025MediumNewsSecurityIndustryA security advisory reports a data leakage and exfiltration vulnerability in Anthropic's Slack MCP Server, a reference implementation now deprecated and unmaintained. The server does not disable link unfurling when posting to channels, so an AI agent that posts links can leak data, such as secrets from a .env file, to third-party servers, and a prompt injection can trigger this. The advisory says the server appears widely used, with 14k+ weekly downloads.
Embrace The RedHosting COM Servers with an MCP Server
Jun 9, 2025LowNewsSecurityIndustryThe author built mcp-com-server, an MCP server that wraps Windows COM and Office automation, exposing tools such as CreateObject, Get/Set Property, InvokeMethod, QueryInterface and ListAllHostedServers. Because any COM object can be instantiated, the server could open Shell.Application or FileSystemObject and perform dangerous operations. The author describes it as a learning prototype and notes that the server can automate Excel and Outlook through Claude.
Fix: The source states a basic mitigation: an Allow List for CLSIDs and ProgIDs, so the server only instantiates allow-listed COM objects, which the author says could be expanded to specific interfaces and methods. It also notes that Claude shows an Allow / Deny confirmation before invoking custom tools by default, which can be disabled or re-enabled per MCP tool in Claude Settings.
Embrace The RedCVE-2025-5277: aws-mcp-server command injection via crafted prompts
May 28, 2025CriticalVulnerabilitySecurityCVE-2025-5277CVE-2025-5277 affects the aws-mcp-server MCP server, which is vulnerable to command injection under CWE-78. An attacker can craft a prompt that, once accessed by the MCP client, runs arbitrary commands on the host system. Snyk scored it CVSS 4.0 9.4 (Critical) with no user privileges required and user interaction required; NIST had not yet provided an assessment.
NVD/CVE DatabaseMCP: Untrusted Servers and Confused Clients, Plus a Sneaky Exploit
May 2, 2025MediumNewsSecurityResearchThe author explains that the Model Context Protocol (MCP) lets LLM apps and agents discover and use external tools at runtime, unlike static setups such as OpenAPI. The author argues that because of prompt injection, MCP tool servers effectively control the client. The post promises a detailed explanation and a novel exploit chain.
Embrace The RedSecuring AI’s New Frontier: The Power of Open Collaboration on MCP Security
Apr 22, 2025InfoResearchIndustrySecurityIndustryThe OWASP GenAI Security Project published research on securing the Model Context Protocol (MCP), which lets AI systems interact with live tools and data. The post summarizes key insights from that work and offers defense-in-depth strategies for developers and defenders building agentic AI applications.
OWASP GenAI Security
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.