In recent developments, the MCP (Model Context Protocol) aimed to unify the AI ecosystem by standardizing connections between models, agents, and tools. Since its inception in 2024, MCP has been widely adopted, with developers creating numerous servers and integrating them into enterprise workflows seamlessly.
The Unseen Vulnerabilities
Despite the widespread adoption of MCP, the surrounding ecosystem has shown significant security weaknesses. Earlier this year, OX Security identified critical vulnerabilities in the source code of MCP, notably within Anthropic’s version, which had over 150 million downloads. Our latest focus shifted to the community-driven servers published in popular MCP marketplaces, where we discovered a lack of rigorous security reviews and controls.
A Marketplace Lacking Oversight
The absence of a robust security review process in MCP marketplaces is reminiscent of past issues faced by platforms like Google Play. Unlike Google’s Bouncer, which scans Android apps for malware, MCP lacks a similar system. This allows anyone to publish a server without sufficient scrutiny, creating a potential hotbed for malicious code to be introduced.
Our research, showcased at RSAC and OWASP, highlighted how developers might over-rely on code repositories, unaware that the running backend code could differ significantly from what’s displayed. This oversight poses considerable risks, as MCP servers can execute unverified backend operations, leading to potential breaches.
Data Governance Concerns
Enterprises have long established stringent data governance policies to ensure safe cloud adoption. However, MCP connections often bypass these protocols. Our analysis of 15,465 publicly indexed MCP servers revealed several alarming insights. Notably, 15.6% of these servers operated outside the United States, including 19 in China and 18 in Russia, which could result in unauthorized data transfers to unapproved jurisdictions.
Additionally, 0.45% of servers were found routing traffic through consumer tunneling services, such as ngrok, while 2.3% had domains that no longer resolved, creating opportunities for misuse if these domains are reacquired.
Future Security Measures
The core issue lies not with the MCP protocol itself but with the misplaced trust in its security. Until marketplaces implement stringent vetting, code signing, and verification processes, enterprises must take proactive measures to secure their systems.
For a detailed understanding of our research, download the report “15,465 MCP Servers, 0 Governance.” Additionally, join our upcoming webinar, “The AI Attack Surface Is Already in Your Cloud,” on October 13, featuring insights from industry experts on navigating AI-related security challenges.
