HomeSecurityPrompt hijacking compromises MCP-based AI workflows

Prompt hijacking compromises MCP-based AI workflows

The Model Context Protocol (MCP) provides IT teams with a standardized way to connect large language models (LLMs) to tools and data sources when developing AI-powered workflows. However, security researchers warn that MCP-based AI workflows can be vulnerable to malicious prompt hijacking attacks if session ID management is implemented in an insecure manner on the MCP servers that facilitate the connection.

See also: CometJacking: One Click Turns Comet AI into a Data Thief

Prompt hijacking
Prompt hijacking compromises MCP-based AI workflows

“Prompt hijacking is a new variant of the vulnerability that constitutes a dangerous attack vector enabled by MCP interaction patterns, as seen in MCP servers that generate predictable session identifiers,” researchers at security firm JFrog in a new report.

An example of how this issue can affect AI workflows and agents is a recent vulnerability found by JFrog in oatpp-mcp , the MCP implementation for Oat++ (oatpp), a popular framework for developing web applications in C++. Listed as CVE-2025-6515 , the vulnerability arises from the fact that oatpp-mcp generates predictable session identifiers for use in its communication with MCP clients, an issue that other MCP servers may also have.

The Model Context Protocol was developed by AI company Anthropic to enable communication between LLMs and external data sources or applications to improve the workflow framework. MCP has been widely adopted and is a key component in the development of AI agents that automate tasks by leveraging external tools. MCP uses a client-server model and supports multiple communication methods. An application or data source that wants to expose its content or functionality to an LLM does so on its own MCP server, and the AI ​​agent, AI chatbot application, or IDE that is the interface for interacting with an LLM via prompts can pull context data from MCP servers through an MCP client implementation.

See also: Notepad++: DLL Hijacking vulnerability allows code execution

Prompt hijacking compromises MCP-based AI workflows
Prompt hijacking compromises MCP-based AI workflows

Let's say a developer working in an IDE that has their favorite model connected tells the model to find the best Python package for a particular task. The model can use the IDE's MCP client to connect to an MCP server designed to search the Python Index (PyPI) and return a package name for that query. MCP servers and clients support various types of communication, including HTTP with Server-Sent Events (SSE).

In this transport mechanism, used by oatpp-mcp, the client initiates a connection to the server with a GET request, and the server creates and responds with a session ID. The client can then use this session ID to send POST requests to the endpoints exposed by the MCP server, and the server will return the results in JSON format.

Session IDs are a way for the MCP server to distinguish between simultaneous connections from different clients, so it is important that they are unique and generated in a cryptographically secure manner — that is, they cannot be predicted. This is a requirement in the new Streamable HTTP specification of the MCP protocol, but was not a requirement in the original SSE transport specification, which means that many MCP servers may not have implemented the uniqueness of session IDs.

For oatpp-mcp, JFrog researchers showed how attackers could open a large number of connections to the MCP server to generate session IDs, then close the connections so that those session IDs are released and assigned to legitimate clients. Attackers can then reuse those IDs to trick the server into generating malicious responses to those clients.

See also: BitlockMove tool allows lateral movement & COM Hijacking

Prompt hijacking compromises MCP-based AI workflows
Prompt hijacking compromises MCP-based AI workflows

Prompt hijacking mitigation measures

MCP server developers should review their implementations and use cryptographically secure random number generators with at least 128 bits of entropy to generate unique session IDs that are not reused. If servers do not do this, the MCP client side can use event IDs for its requests to mitigate this issue by only accepting responses with the same event ID. As with sessions, these event IDs must be unpredictable. Unfortunately, researchers have found that many MCP clients use incremental event IDs that can be brute-forced.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS