MCP is reportedly vulnerable to Context Poisoning, and OWASP has listed it as an LLM01 vulnerability affecting more than 100k sites

DETECTED ISSUE: The LLM semantic validation score is below the configured threshold
FIX HINT: It is recommended to manually review or automatically fix this translation

robot
Abstract generation in progress
AIMPACT message, April 27 (UTC+8): MCP has serious security vulnerabilities, and multiple confirmed enterprise incidents in 2025 have already proven the threat. Anthropic introduced MCP in November 2024, using the JSON-RPC 2.0 protocol standard to normalize AI agent tool calls, likened to “AI’s USB-C.” Within months, it gained over 27,000 stars, and companies including Stripe, OpenAI, and Microsoft subsequently integrated it. But its architecture has a fundamental flaw: when each MCP server connects, it directly injects the tool description into the agent’s context window. A malicious server can exploit trust-model weaknesses to carry out Context Poisoning attacks. OWASP has listed prompt injection as the LLM01 top vulnerability. Real attacks in 2025 have been frequent: Asana (May) saw tenant isolation fail in its MCP integration, impacting more than 1,000 enterprises; a WordPress AI Engine plugin (June) exposed vulnerabilities affecting more than 100k sites due to privilege escalation; Supabase + Cursor caused agents to leak private tokens via prompt injection. MCPTox benchmark tests show that models such as o1-mini and DeepSeek-R1 achieve attack success rates above 60% under adversarial tool descriptions. Although Claude Desktop, Cursor, GitHub Copilot, and others natively support MCP, experts advise treating MCP servers as untrusted input, limiting agent permissions, and requiring human approval for critical actions.
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pinned