Full Report
In 2024, MCP (Model Context Protocol) set out to become the USB-C of AI: one standard for connecting models, agents, and IDEs to tools and data. The protocol delivered. Thousands of developers built servers, and enterprises plugged them into agent workflows. The ecosystem around it fell short. Earlier this year, our team at OX Security, traced critical vulnerabilities in Anthropic's MCP
Analysis Summary
# Vulnerability: Governance and Supply Chain Risks in MCP Server Ecosystem
## CVE Details
* **CVE ID:** Not specifically assigned in the provided article (Referenced as "critical vulnerabilities in Anthropic's MCP source code" discovered by OX Security).
* **CVSS Score:** N/A (General ecosystem risk assessment)
* **CWE:**
* CWE-1357: Reliance on Uncontrolled Component
* CWE-829: Inclusion of Functionality from Untrusted Control Sphere
* CWE-918: Server-Side Request Forgery (SSRF) / Prompt Injection
## Affected Systems
* **Products:** Model Context Protocol (MCP) Servers
* **Versions:** Community-published servers across 5 major MCP registries.
* **Configurations:** AI Agents/IDEs configured to connect to third-party or remote MCP servers for tool and data access.
## Vulnerability Description
The flaw is not a single code bug but a **systemic supply chain vulnerability** within the MCP ecosystem. The protocol allows AI agents to connect to remote servers to execute code and access data. OX Security identified that:
1. **Lack of Vetting:** Marketplaces lack automated security scanning (no "Bouncer" equivalent), allowing malicious servers to be published.
2. **Code Divergence:** Remote MCP servers can execute backend code that differs from their public GitHub repositories, rendering traditional code reviews ineffective.
3. **Dangling Domains:** 2.3% of indexed servers point to expired domains, allowing attackers to hijack established server identities for $4–$12.
4. **Data Residency Violations:** 15.6% of servers resolve to infrastructure in high-risk jurisdictions (China, Russia), bypassing enterprise data governance.
## Exploitation
* **Status:** PoC available (referenced in the OX Security report regarding Prompt Injection).
* **Complexity:** Low to Medium.
* **Attack Vector:** Network.
## Impact
* **Confidentiality:** High (Sensitive data sent to AI agents can be exfiltrated to unauthorized jurisdictions or hijacked servers).
* **Integrity:** High (Attackers can modify server responses to influence AI agent behavior via prompt injection).
* **Availability:** Medium (Dangling domains lead to service interruptions or redirected traffic).
## Remediation
### Patches
* There is no single patch as this is an ecosystem-wide architectural risk. Users must update their **Anthropic MCP source code** to the latest versions to mitigate previously identified core vulnerabilities.
### Workarounds
* **Self-Hosting:** Host MCP servers internally rather than connecting to public endpoints.
* **Domain Verification:** Audit all configured MCP endpoints to ensure they do not point to expired or consumer-tunneled (e.g., ngrok) domains.
* **Egress Filtering:** Restrict agent network access to approved IP ranges and US-based infrastructure.
## Detection
* **Indicators of Compromise:**
* Traffic routing through consumer tunneling services (ngrok-free).
* MCP server hostnames resolving to unexpected geographic locations (Russia/China).
* Discrepancies between public repository code and server response behavior.
* **Detection Methods:**
* Network flow analysis to identify unauthorized MCP server connections.
* Prompt injection testing on all third-party tool integrations.
## References
* OX Security Research: hxxps://www[.]ox[.]security/ebooks/15465-mcp-servers-0-governance/
* The Hacker News Report: hxxps://thehackernews[.]com/2026/10/welcome-to-jungle-what-we-found-inside.html
* Anthropic MCP Documentation: hxxps://modelcontextprotocol[.]io/