HomeRisk ManagementsMCP Creating Major Governance Gaps, Researchers Warn

MCP Creating Major Governance Gaps, Researchers Warn

Published on

spot_img

Growing Concerns Over Model Context Protocol (MCP) and Cybersecurity Risks

Recent research conducted by Ox Security has raised significant alarms regarding the Model Context Protocol (MCP) servers, which are increasingly seen as creating a dangerous enterprise governance gap that may compromise cybersecurity initiatives as artificial intelligence (AI) applications continue to expand. According to the detailed findings presented in their report entitled 15,465 MCP Servers, 0 Governance, the issues stemming from these protocols could prove detrimental to organizational security frameworks.

MCP serves as a bridge connecting AI applications to external tools and data sources in a consistent, standardized format. This innovative approach simplifies the developer’s task by removing the need to write bespoke code for each connection that links AI functionalities with APIs or databases. However, in facilitating these streamlined connections, the report warns that organizations may inadvertently expose themselves to a variety of cloud security vulnerabilities. These vulnerabilities stand in stark contrast to existing safeguards, such as data residency requirements, zero trust boundaries, granular Identity and Access Management (IAM) policies, and the rigorous practices of continuous supply-chain auditing.

The analysis performed by Ox Security spanned three public registries: the mcp-official-registry, the cline-marketplace, and the github-mcp-registry. Through this robust examination, it was found that almost 16% of the 5,095 unique hostnames studied resolved to locations outside the United States, including countries recognized for their less stringent cybersecurity practices, such as Russia and China. The report pointed out a critical flaw, stating, “MCP has no protocol-level concept of geographic region.” This lack of geographical awareness implies that while an enterprise may enforce strict data residency controls for its cloud workloads, its AI agents may still connect to external servers beyond those protections.

Further exemplifying the threats posed by the MCP servers, the report noted that over 2% of the hostnames no longer resolved, with some being unregistered and available for purchase. This scenario presents a potential risk where a malicious actor could easily impersonate these servers and exploit the vulnerabilities tied to them.

The security researchers at Ox Security conducted an experiment using Claude Code with Haiku 3.5. They found that granting a single "always-allow" permission enabled subsequent malicious actions without requiring any human intervention. The exercise revealed that when a malicious MCP server initially requested access to a benign file and received user approval, it subsequently proceeded to solicit sensitive files, such as .env files, without further prompts. Anthropic, the organization behind the model, responded by stating that once an "always-allow" permission is granted, this behavior is expected, highlighting a concerning gap in model-level detection of malicious content, which they referred to as a best-effort heuristic rather than a robust security measure.

Heightened MCP Risk Landscape

In a separate examination, a report by Backslash Security, published in June 2025, identified vulnerabilities within 7,000 MCP servers, revealing hundreds of systems that could be accessed by anyone on the same local network due to a vulnerability termed “NeighborJack.” Alarmingly, approximately 70 instances exhibited critical flaws, including improper input handling and excessive permissions.

Following up in April 2026, Ox Security unveiled another significant report declaring a “critical, systemic” vulnerability within MCP that could permit arbitrary command execution on any susceptible system. The vendor indicated that this issue could potentially expose up to 200 open source projects, 150 million downloads, 7,000 publicly accessible servers, and as many as 200,000 vulnerable instances.

Notably, the document criticized the vulnerability not merely as a conventional flaw but as “an architectural design decision baked into Anthropic’s official MCP SDKs across every supported programming language.” Despite the severity of these findings, Anthropic dismissed the report, labeling the vulnerabilities as “expected behavior.” The company committed to working within the AI supply chain to address the individual open source projects affected by these shortcomings.

As enterprises continue to navigate the complexities of integrating AI into their operations, the implications of Ox Security’s research underscore the critical importance of stringent governance and security measures in the deployment of Model Context Protocol servers. The report serves as a wake-up call, urging organizations to reassess their existing cybersecurity frameworks to ensure they are adequately fortified against emerging threats posed by the very technologies meant to enhance operational efficiencies.

Source link

Latest articles

James Moore: AI Security and Governance—Why Most Organizations Are Flying Blind

Understanding the Challenges of AI Adoption and Governance The rapid pace of artificial intelligence (AI)...

670 Jev Domains Registered Following Launch as Fraudulent AI Marketplaces Exploit Users

The Rise of Lookalike Domains Targeting TypeSafe AI’s Jev Decision Model In a startling development...

NetScaler Administrators Urged to Patch Critical Zero-Day Vulnerabilities in ADC and Gateway Immediately

Citrix Enhances Security for NetScaler Appliances Amid Vulnerabilities In an ever-evolving digital landscape, enterprise networks...

Stolen AI Credentials Fuel Expanding LLM Proxy Economy

Rising Concern: Chinese-Speaking Threat Actor Exploits AI APIs for Credential Theft Recent findings from Gambit...

More like this

James Moore: AI Security and Governance—Why Most Organizations Are Flying Blind

Understanding the Challenges of AI Adoption and Governance The rapid pace of artificial intelligence (AI)...

670 Jev Domains Registered Following Launch as Fraudulent AI Marketplaces Exploit Users

The Rise of Lookalike Domains Targeting TypeSafe AI’s Jev Decision Model In a startling development...

NetScaler Administrators Urged to Patch Critical Zero-Day Vulnerabilities in ADC and Gateway Immediately

Citrix Enhances Security for NetScaler Appliances Amid Vulnerabilities In an ever-evolving digital landscape, enterprise networks...