logo

New Prompt Injection Attack Vectors Through MCP Sampling

ID: 1c0bb78c-cc8b-5256-abb4-2e8fbeec2801

STIX ID: report--1c0bb78c-cc8b-5256-abb4-2e8fbeec2801

Feed Name: Palo Alto Networks Unit 42

Threat Score
70/100

Date Published: 2025-12-05

Date Updated: 2026-04-28

Author: Yongzhe Huang, Akshata Rao, Changjiang Li, Yang Ji and Wenjun Hu

...
...

This report analyzes security risks in the Model Context Protocol (MCP) sampling feature, demonstrating three proof-of-concept attacks — resource/token theft via hidden prompt content, persistent prompt injection that hijacks conversation behavior, and covert tool invocation enabling unauthorized file writes — and provides detection and mitigation recommendations to limit prompt injection, enforce access controls, and filter/limit sampling requests.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.