Top MCP Security Vulnerabilities Every AI Team Should Know
Model context protocol (MCP) was supposed to become the standard method of creating a consistent and safe interface for AI agent(s) and the data source(s). But for as much as it does good, there are inherent security vulnerabilities that plague MCPs. Some would say MCPs are a ticking time bomb.
To help you understand and manage the risks, we’ve created a list of the top MCP security vulnerabilities every AI team should know about.
MCP Overview
Based on recent 2025 research and security analysis from Cyber Sierra, MCP servers, which enable AI models to connect with local data and tools, face significant security risks.
Essentially, MCP acts as a universal adapter for AI. Through an MCP client, it allows an LLM to query or command MCP servers that interface with various tools, databases, files, or APIs in real time. This allows AI agents to dynamically retrieve context (for example, documents, database entries) or perform actions (such as running a shell command or calling a cloud API to fulfill user requests), overcoming the static knowledge limitation of the LLM’s training data.
That all sounds great, but connecting AI to live systems in this way greatly expands the attack surface, making MCP protection essential for AI teams.
Cyber Sierra Data
Researchers have documented a 327% increase in attacks targeting machine communication protocols since 2023, a number that’s difficult to fathom unless you understand the mechanisms that are so vulnerable and exposed to risks.
From the Cyber Sierra research, the statistics show:
- 43% of tested MCP implementations contained command injection vulnerabilities.
- 30% of tested MCPs had SSRF (Server-Side Request Forgery) vulnerabilities.
- 22% of tested MCPs allowed path traversal/arbitrary file read.
- Approximately 7,000 MCP servers (roughly half of the analyzed total) were found to be exposed on the public internet. Many of them were without authentication.
- 45% of vendors dismissed these findings as “theoretical” or “acceptable risks.”
As you can see, there are big issues stemming from the Anthropic-developed ecosystem (Linux Foundation’s Agentic AI initiative) that was released as an open standard in 2024.
The Top MCP Security Vulnerabilities Every AI Team Should Know
Inadequate Authentication and Authorization
Identity and permission checks are a critical weakness in early MCP implementations. If an MCP server doesn’t correctly verify who is requesting an action and whether they have permission to perform it, it can become completely confused, or what’s known as a “confused deputy.” With that, it will then start performing sensitive operations on behalf of an attacker or unprivileged user.
For example, an MCP server might have access to corporate databases or admin APIs, but without robust authentication, an attacker could directly invoke those tools via the MCP server and retrieve or modify data they shouldn’t. The MCP specification does include an OAuth-based auth scheme, but the initial spec had gaps that conflicted with enterprise practices.
NeuralTrust’s AI Gateway provides a secure and scalable way to manage AI models and applications. It helps businesses streamline AI operations while improving security, performance, and control.
Command Injection and Unauthorized Code Execution
A big issue is that many MCP servers wrap existing system commands or scripts to fulfill tasks, for example, a tool to read a file or run a shell command. If user-controlled input flows into these commands without sanitization, attackers can exploit command injection or similar exploits.
For example, an MCP server tool might accept a filename to read. An attacker could craft a filename like “; rm -rf / important_data ;” to execute malicious OS commands. Red Hat’s security team notes that local MCP servers may execute arbitrary code, so any parameters passed from the LLM should be carefully validated to prevent shell metacharacters or path traversal sequences.
In fact, researchers have already identified real examples of MCP server code vulnerable to command injection.
Prompt Injection and Context Manipulation
Prompt injection, feeding malicious or unexpected instructions into the model’s input, is a serious infrastructure threat.
Because MCP pipelines automatically feed external data and tool outputs into the LLM, an attacker can craft inputs that poison the context. For example, hiding a malicious instruction in a database record or document could cause the LLM to select a harmful action or leak data when that record is fetched via MCP. Upwind’s researchers describe context poisoning, where attackers manipulate upstream data, such as tickets, files, etc., to influence the LLM without altering the model itself.
In practice, a prompt injection might trick an agent into revealing confidential info or performing an unintended action.
Other Serious Security Vulnerabilities
We’d say those are the most problematic, but some of the other serious security vulnerabilities include
- Malicious or compromised tools (Tool Injection)
- Session hijacking and replay attacks
- Agentic Denial-of-Service (DoS)
- Protocol exploitation and evasion
- Lack of monitoring and “shadow” deployments
Essentially, MCP is a massive risk to clients and enterprises, but there are security solutions, such as the MCP protection services Datadome provides, that can build trust in every MCP interaction including agentic AI.
DataDome’s Approach to MCP Protection
DataDome’s approach to MCP protection is sophisticated and comprehensive, allowing users to gain full visibility into AI agent traffic. From there, they can then enforce policy controls and block unauthorized or fraudulent requests simultaneously.
As a specialist cybersecurity company with expertise in bot and fraud prevention, they’ve introduced a dedicated solution to secure MCP servers and agentic AI traffic. As you can see, MCP was not designed with security in mind and introduces an entirely new attack surface for organizations.
Here’s how DataDome does it:
- Real-Time Traffic Visibility and Classification: DataDome monitors every request reaching MCP servers. They effortlessly provide full visibility into agent-driven interactions, with monitoring even happening with high granularity down to analyzing JSON-RPC payload structures, without blocking or slowing down legitimate usage.
- Automated Threat Detection and Blocking: The platform operates in autopilot protection mode at the network edge, meaning it will automatically block malicious agent traffic before it reaches the MCP server.
- Trust & Identity Enforcement: DataDome establishes a continuous trust model for agentic AI interactions. They verify the identity, origin, and behavior of each agent session to ensure it stays within safe boundaries.
- Seamless Integration and Multi-Layer Defense: To protect MCP servers without adding complexity, DataDome integrates using standard modules, including popular frameworks like Node.js, MCP servers, or AWS Lambda@Edge for API gateways. You get zero latency and the first native integration for FastMCP using the leading python framework and fastAPI deployments within minutes.
MCP security vulnerabilities are massive, but they are avoidable with the correct MCP protection and understanding of the potential vulnerabilities; the ecosystem doesn’t need to be so vulnerable.