New Prompt Injection Attack via Malicious MCP Servers Let Attackers Drain Resources
ID: 99040948-759e-59c3-9772-26f77038c91c
STIX ID: report--99040948-759e-59c3-9772-26f77038c91c
Feed Name: cybersecurityNews.com
Security researchers disclosed critical vulnerabilities in the Model Context Protocol (MCP) sampling feature used by LLM-integrated applications, showing how malicious MCP servers can inject hidden instructions into prompts/responses to perform resource theft (unauthorized compute and API credit consumption), conversation hijacking (persistent alteration of assistant behavior), and covert tool invocation (unauthorized file operations and potential data exfiltration). The report attributes the issue to MCP sampling’s implicit trust model and lack of built-in security controls, demonstrates proof-of-concept attacks on a coding copilot, and recommends layered defenses including request sanitization, response filtering, access controls, operation-specific token limits, and explicit approvals for tool execution.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
