MCP Configuration Poisoning: Owning Your Machine With Just A Text File
ID: dc240258-f45d-5b60-83c1-95804b798ba0
STIX ID: report--dc240258-f45d-5b60-83c1-95804b798ba0
Feed Name: Checkmarx Zero
This report describes “MCP Configuration Poisoning,” a supply-chain style vulnerability where attackers embed malicious commands in mcp.json configuration files that tools (IDEs, scanners, CI/CD, agents) may automatically execute, enabling Remote Code Execution. The author demonstrates a proof-of-concept against Snyk’s Agent Scan (now fixed), outlines how such poisoned configs can reach victims (malicious repos, PRs, dependencies), and recommends defenses: sandboxing, blocking suspicious shell patterns, and robust human-in-the-loop protections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
