HomeSecurityTop 25 MCP Vulnerabilities Exploited by AI Agents

Top 25 MCP Vulnerabilities Exploited by AI Agents

MCP has become an integral part of the expansion of AI Agents, but it comes with its own vulnerabilities. The Model Context Protocol (MCP), developed by Anthropic and released as an open standard in 2024, is the de facto method for ensuring a consistent and secure interface between an AI Agent and its data source. It defines how AI Agents interact with tools, other Agents, data, and the environment in a secure and controlled manner whenever required.

See also: iOS 26 may get a major AI boost with MCP

MCP

It is therefore a fundamental requirement for the effective operation of AI Agents. However, like all software, MCP has areas that can be abused by malicious users. Recently, a potential attack on ChatGPT's calendar integration was described, allowing an email calendar invitation to deliver a jailbreak to ChatGPT, without requiring any user interaction.

AI specialist firm Adversahas published an analysis of the top 25 MCP vulnerabilities, describing it as the most comprehensive MCP vulnerability analysis to date. OWASP is known to be planning its own Top Ten list for MCP, but this is not yet available and will likely be limited to ten vulnerabilities. Adversa is not trying to compete with OWASP, but aims to provide direct assistance for companies developing and implementing AI Agent solutions today.

Adversa's basic vulnerability table includes a proposed official name, an impact score, an exploitability rating, and a link to additional third-party explanations. The ranking score is developed through a severity algorithm: 40% impact, 30% exploitability, 20% prevalence, and 10% remediation complexity.

See also: Hackers abuse MCP servers to collect sensitive data

AI chips

It is no surprise that prompt injection remains the perfect trap, combining critical impact with trivial exploitability and ranks as the #1 vulnerability. Less well known is the MCP Preference Management Attack (MPMA), which has low impact and complex exploitability, ranking at #24.

The document defaults to the first description of a vulnerability for further reading, but these links are not permanent. The document also provides a practical security and mitigation checklist, including immediate steps, a defense-in-depth strategy, and a mitigation timeline.

The defense strategy includes four layers: protocol layer, application layer, AI-specific defenses, and infrastructure. Examples include enforcing TLS for all communications at the protocol layer and using parameterized queries for database operations at the application layer. The mitigation timeline spans a three-month period, starting with implementing authentication at all exposed points and including redesigning the architecture for a zero-trust model in the third month.

See also: Asana says MCP AI feature exposed customer data

Top 25 MCP Vulnerabilities Exploited by AI Agents

Adversa has created the first comprehensive guide to MCP vulnerabilities impacting the transition from human intelligence to automated AI. This guide is designed to help IT and security departments understand and mitigate these vulnerabilities.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS