logo

New Prompt Injection Attack via Malicious MCP Servers Let Attackers Drain Resources

ID: 99040948-759e-59c3-9772-26f77038c91c

STIX ID: report--99040948-759e-59c3-9772-26f77038c91c

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2025-12-09

Date Updated: 2026-04-21

Author: Abinaya

...
...

Security researchers disclosed critical vulnerabilities in the Model Context Protocol (MCP) sampling feature used by LLM-integrated applications, showing how malicious MCP servers can inject hidden instructions into prompts/responses to perform resource theft (unauthorized compute and API credit consumption), conversation hijacking (persistent alteration of assistant behavior), and covert tool invocation (unauthorized file operations and potential data exfiltration). The report attributes the issue to MCP sampling’s implicit trust model and lack of built-in security controls, demonstrates proof-of-concept attacks on a coding copilot, and recommends layered defenses including request sanitization, response filtering, access controls, operation-specific token limits, and explicit approvals for tool execution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.