logo

11 Emerging AI Security Risks with MCP (Model Context Protocol)

ID: cddaa59c-4be6-5779-8ca2-e5eef558d959

STIX ID: report--cddaa59c-4be6-5779-8ca2-e5eef558d959

Feed Name: Checkmarx Zero

Threat Score
55/100

Date Published: 2025-11-25

Date Updated: 2026-04-27

Author: Tal Folkman

...
...

This Checkmarx report analyzes security risks introduced by the Model Context Protocol (MCP), describing its host/client/server architecture and cataloging 11 emerging threat categories—including prompt injection, tool and schema poisoning, confused-deputy authorization flaws, supply-chain/typosquatting attacks, context/configuration poisoning, credential exposure, and excessive privilege abuse—illustrating each with examples and mitigations; it emphasizes that MCP extends traditional AppSec and supply-chain concerns into AI-driven interactions and recommends applying secure coding, least-privilege, validation, provenance checks, and AI-aware threat modeling to secure the ecosystem.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.