logo

MCP Configuration Poisoning: Owning Your Machine With Just A Text File

ID: dc240258-f45d-5b60-83c1-95804b798ba0

STIX ID: report--dc240258-f45d-5b60-83c1-95804b798ba0

Feed Name: Checkmarx Zero

Threat Score
70/100

Date Published: 2026-07-23

Date Updated: 2026-07-23

Author: Bruno Dias

...
...

This report describes “MCP Configuration Poisoning,” a supply-chain style vulnerability where attackers embed malicious commands in mcp.json configuration files that tools (IDEs, scanners, CI/CD, agents) may automatically execute, enabling Remote Code Execution. The author demonstrates a proof-of-concept against Snyk’s Agent Scan (now fixed), outlines how such poisoned configs can reach victims (malicious repos, PRs, dependencies), and recommends defenses: sandboxing, blocking suspicious shell patterns, and robust human-in-the-loop protections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.